// SPDX-License-Identifier: MIT pragma solidity ^0.8.20 ^0.8.24; // lib/openzeppelin-contracts/contracts/utils/Context.sol // OpenZeppelin Contracts (last updated v5.0.1) (utils/Context.sol) /** * @dev Provides information about the current execution context, including the * sender of the transaction and its data. While these are generally available * via msg.sender and msg.data, they should not be accessed in such a direct * manner, since when dealing with meta-transactions the account sending and * paying for execution may not be the actual sender (as far as an application * is concerned). * * This contract is only required for intermediate, library-like contracts. */ abstract contract Context { function _msgSender() internal view virtual returns (address) { return msg.sender; } function _msgData() internal view virtual returns (bytes calldata) { return msg.data; } function _contextSuffixLength() internal view virtual returns (uint256) { return 0; } } // lib/openzeppelin-contracts/contracts/utils/Errors.sol // OpenZeppelin Contracts (last updated v5.1.0) (utils/Errors.sol) /** * @dev Collection of common custom errors used in multiple contracts * * IMPORTANT: Backwards compatibility is not guaranteed in future versions of the library. * It is recommended to avoid relying on the error API for critical functionality. * * _Available since v5.1._ */ library Errors { /** * @dev The ETH balance of the account is not enough to perform the operation. */ error InsufficientBalance(uint256 balance, uint256 needed); /** * @dev A call to an address target failed. The target may have reverted. */ error FailedCall(); /** * @dev The deployment failed. */ error FailedDeployment(); /** * @dev A necessary precompile is missing. */ error MissingPrecompile(address); } // src/interfaces/IAggregatorV3.sol /// @notice Chainlink AggregatorV3 read surface. /// @dev Base tokenized-equity feeds use this standard interface. Note they have no /// heartbeat while equity markets are closed and hold the last close instead, /// so `updatedAt` going stale on a weekend is expected, not a fault. interface IAggregatorV3 { function decimals() external view returns (uint8); function description() external view returns (string memory); function latestRoundData() external view returns (uint80 roundId, int256 answer, uint256 startedAt, uint256 updatedAt, uint80 answeredInRound); } // src/interfaces/IAmmFactories.sol /// @notice Uniswap v3 factory, keyed by fee tier. interface IUniswapV3Factory { function getPool(address tokenA, address tokenB, uint24 fee) external view returns (address pool); } /// @notice Aerodrome Slipstream (concentrated liquidity) factory, keyed by tick spacing. interface ISlipstreamFactory { function getPool(address tokenA, address tokenB, int24 tickSpacing) external view returns (address pool); } /// @notice Aerodrome's Voter, the registry that says which gauge is canonical for a pool. /// @dev This is the discriminator H-01 turns on. A gauge address by itself proves nothing — /// anyone can deploy a contract with a `deposit(uint256)`. `voter.gauges(pool)` is the /// only on-chain statement that a given gauge is *the* gauge for a given pool, and the /// pool in turn is derived from the position, not from the caller. interface IAerodromeVoter { function gauges(address pool) external view returns (address); } /// @notice The one field of a concentrated-liquidity pool's `slot0` we need: its price. /// @dev Read by staticcall and decoded as a single word rather than through this interface, /// because Uniswap v3 and Slipstream disagree about the later fields of the tuple and /// agree about the first. Declared here for documentation. interface IPoolPrice { function slot0() external view returns (uint160 sqrtPriceX96); } // lib/openzeppelin-contracts/contracts/utils/introspection/IERC165.sol // OpenZeppelin Contracts (last updated v5.1.0) (utils/introspection/IERC165.sol) /** * @dev Interface of the ERC-165 standard, as defined in the * https://eips.ethereum.org/EIPS/eip-165[ERC]. * * Implementers can declare support of contract interfaces, which can then be * queried by others ({ERC165Checker}). * * For an implementation, see {ERC165}. */ interface IERC165 { /** * @dev Returns true if this contract implements the interface defined by * `interfaceId`. See the corresponding * https://eips.ethereum.org/EIPS/eip-165#how-interfaces-are-identified[ERC section] * to learn more about how these ids are created. * * This function call must use less than 30 000 gas. */ function supportsInterface(bytes4 interfaceId) external view returns (bool); } // lib/openzeppelin-contracts/contracts/token/ERC20/IERC20.sol // OpenZeppelin Contracts (last updated v5.1.0) (token/ERC20/IERC20.sol) /** * @dev Interface of the ERC-20 standard as defined in the ERC. */ interface IERC20 { /** * @dev Emitted when `value` tokens are moved from one account (`from`) to * another (`to`). * * Note that `value` may be zero. */ event Transfer(address indexed from, address indexed to, uint256 value); /** * @dev Emitted when the allowance of a `spender` for an `owner` is set by * a call to {approve}. `value` is the new allowance. */ event Approval(address indexed owner, address indexed spender, uint256 value); /** * @dev Returns the value of tokens in existence. */ function totalSupply() external view returns (uint256); /** * @dev Returns the value of tokens owned by `account`. */ function balanceOf(address account) external view returns (uint256); /** * @dev Moves a `value` amount of tokens from the caller's account to `to`. * * Returns a boolean value indicating whether the operation succeeded. * * Emits a {Transfer} event. */ function transfer(address to, uint256 value) external returns (bool); /** * @dev Returns the remaining number of tokens that `spender` will be * allowed to spend on behalf of `owner` through {transferFrom}. This is * zero by default. * * This value changes when {approve} or {transferFrom} are called. */ function allowance(address owner, address spender) external view returns (uint256); /** * @dev Sets a `value` amount of tokens as the allowance of `spender` over the * caller's tokens. * * Returns a boolean value indicating whether the operation succeeded. * * IMPORTANT: Beware that changing an allowance with this method brings the risk * that someone may use both the old and the new allowance by unfortunate * transaction ordering. One possible solution to mitigate this race * condition is to first reduce the spender's allowance to 0 and set the * desired value afterwards: * https://github.com/ethereum/EIPs/issues/20#issuecomment-263524729 * * Emits an {Approval} event. */ function approve(address spender, uint256 value) external returns (bool); /** * @dev Moves a `value` amount of tokens from `from` to `to` using the * allowance mechanism. `value` is then deducted from the caller's * allowance. * * Returns a boolean value indicating whether the operation succeeded. * * Emits a {Transfer} event. */ function transferFrom(address from, address to, uint256 value) external returns (bool); } // lib/openzeppelin-contracts/contracts/token/ERC721/IERC721Receiver.sol // OpenZeppelin Contracts (last updated v5.1.0) (token/ERC721/IERC721Receiver.sol) /** * @title ERC-721 token receiver interface * @dev Interface for any contract that wants to support safeTransfers * from ERC-721 asset contracts. */ interface IERC721Receiver { /** * @dev Whenever an {IERC721} `tokenId` token is transferred to this contract via {IERC721-safeTransferFrom} * by `operator` from `from`, this function is called. * * It must return its Solidity selector to confirm the token transfer. * If any other value is returned or the interface is not implemented by the recipient, the transfer will be * reverted. * * The selector can be obtained in Solidity with `IERC721Receiver.onERC721Received.selector`. */ function onERC721Received( address operator, address from, uint256 tokenId, bytes calldata data ) external returns (bytes4); } // src/interfaces/INonfungiblePositionManager.sol /// @notice Aerodrome Slipstream NonfungiblePositionManager. /// @dev VERIFIED, not assumed. Every selector below was probed against the deployed /// bytecode at 0x827922686190790b37229fd06084350E74485b72 on Base: /// mint((address,address,int24,int24,int24,uint256,uint256,uint256,uint256,address,uint256,uint160)) /// -> 0xb5007d1f PRESENT /// the Uniswap-v3 shape (uint24 fee, no sqrtPriceX96) -> 0x88316456 ABSENT /// So Slipstream keys by tickSpacing, not fee tier, and carries sqrtPriceX96 so a /// mint can create the pool. See test/fork/PolTreasuryFork.t.sol. interface INonfungiblePositionManager { struct MintParams { address token0; address token1; int24 tickSpacing; int24 tickLower; int24 tickUpper; uint256 amount0Desired; uint256 amount1Desired; uint256 amount0Min; uint256 amount1Min; address recipient; uint256 deadline; uint160 sqrtPriceX96; } struct IncreaseLiquidityParams { uint256 tokenId; uint256 amount0Desired; uint256 amount1Desired; uint256 amount0Min; uint256 amount1Min; uint256 deadline; } struct DecreaseLiquidityParams { uint256 tokenId; uint128 liquidity; uint256 amount0Min; uint256 amount1Min; uint256 deadline; } struct CollectParams { uint256 tokenId; address recipient; uint128 amount0Max; uint128 amount1Max; } function mint(MintParams calldata params) external payable returns (uint256 tokenId, uint128 liquidity, uint256 amount0, uint256 amount1); function increaseLiquidity(IncreaseLiquidityParams calldata params) external payable returns (uint128 liquidity, uint256 amount0, uint256 amount1); function decreaseLiquidity(DecreaseLiquidityParams calldata params) external payable returns (uint256 amount0, uint256 amount1); function collect(CollectParams calldata params) external payable returns (uint256 amount0, uint256 amount1); function positions(uint256 tokenId) external view returns ( uint96 nonce, address operator, address token0, address token1, int24 tickSpacing, int24 tickLower, int24 tickUpper, uint128 liquidity, uint256 feeGrowthInside0LastX128, uint256 feeGrowthInside1LastX128, uint128 tokensOwed0, uint128 tokensOwed1 ); function factory() external view returns (address); function ownerOf(uint256 tokenId) external view returns (address); } /// @notice Minimal Aerodrome gauge surface for staking a Slipstream position. interface ISlipstreamGauge { function deposit(uint256 tokenId) external; function withdraw(uint256 tokenId) external; function getReward(uint256 tokenId) external; function rewardToken() external view returns (address); } // src/interfaces/ISwapRouters.sol /// @notice Uniswap v3 SwapRouter02 exact-input-single. interface IUniswapV3SwapRouter { struct ExactInputSingleParams { address tokenIn; address tokenOut; uint24 fee; address recipient; uint256 amountIn; uint256 amountOutMinimum; uint160 sqrtPriceLimitX96; } function exactInputSingle(ExactInputSingleParams calldata params) external payable returns (uint256 amountOut); } /// @notice Aerodrome Slipstream router. Same shape as Uniswap v3 except it keys pools by /// tick spacing rather than fee tier, and carries a deadline. interface ISlipstreamSwapRouter { struct ExactInputSingleParams { address tokenIn; address tokenOut; int24 tickSpacing; address recipient; uint256 deadline; uint256 amountIn; uint256 amountOutMinimum; uint160 sqrtPriceLimitX96; } function exactInputSingle(ExactInputSingleParams calldata params) external payable returns (uint256 amountOut); } // src/interfaces/IWETH.sol interface IWETH { function deposit() external payable; function withdraw(uint256 amount) external; } // lib/openzeppelin-contracts/contracts/utils/Panic.sol // OpenZeppelin Contracts (last updated v5.1.0) (utils/Panic.sol) /** * @dev Helper library for emitting standardized panic codes. * * ```solidity * contract Example { * using Panic for uint256; * * // Use any of the declared internal constants * function foo() { Panic.GENERIC.panic(); } * * // Alternatively * function foo() { Panic.panic(Panic.GENERIC); } * } * ``` * * Follows the list from https://github.com/ethereum/solidity/blob/v0.8.24/libsolutil/ErrorCodes.h[libsolutil]. * * _Available since v5.1._ */ // slither-disable-next-line unused-state library Panic { /// @dev generic / unspecified error uint256 internal constant GENERIC = 0x00; /// @dev used by the assert() builtin uint256 internal constant ASSERT = 0x01; /// @dev arithmetic underflow or overflow uint256 internal constant UNDER_OVERFLOW = 0x11; /// @dev division or modulo by zero uint256 internal constant DIVISION_BY_ZERO = 0x12; /// @dev enum conversion error uint256 internal constant ENUM_CONVERSION_ERROR = 0x21; /// @dev invalid encoding in storage uint256 internal constant STORAGE_ENCODING_ERROR = 0x22; /// @dev empty array pop uint256 internal constant EMPTY_ARRAY_POP = 0x31; /// @dev array out of bounds access uint256 internal constant ARRAY_OUT_OF_BOUNDS = 0x32; /// @dev resource error (too large allocation or too large array) uint256 internal constant RESOURCE_ERROR = 0x41; /// @dev calling invalid internal function uint256 internal constant INVALID_INTERNAL_FUNCTION = 0x51; /// @dev Reverts with a panic code. Recommended to use with /// the internal constants with predefined codes. function panic(uint256 code) internal pure { assembly ("memory-safe") { mstore(0x00, 0x4e487b71) mstore(0x20, code) revert(0x1c, 0x24) } } } // lib/openzeppelin-contracts/contracts/utils/ReentrancyGuard.sol // OpenZeppelin Contracts (last updated v5.1.0) (utils/ReentrancyGuard.sol) /** * @dev Contract module that helps prevent reentrant calls to a function. * * Inheriting from `ReentrancyGuard` will make the {nonReentrant} modifier * available, which can be applied to functions to make sure there are no nested * (reentrant) calls to them. * * Note that because there is a single `nonReentrant` guard, functions marked as * `nonReentrant` may not call one another. This can be worked around by making * those functions `private`, and then adding `external` `nonReentrant` entry * points to them. * * TIP: If EIP-1153 (transient storage) is available on the chain you're deploying at, * consider using {ReentrancyGuardTransient} instead. * * TIP: If you would like to learn more about reentrancy and alternative ways * to protect against it, check out our blog post * https://blog.openzeppelin.com/reentrancy-after-istanbul/[Reentrancy After Istanbul]. */ abstract contract ReentrancyGuard { // Booleans are more expensive than uint256 or any type that takes up a full // word because each write operation emits an extra SLOAD to first read the // slot's contents, replace the bits taken up by the boolean, and then write // back. This is the compiler's defense against contract upgrades and // pointer aliasing, and it cannot be disabled. // The values being non-zero value makes deployment a bit more expensive, // but in exchange the refund on every call to nonReentrant will be lower in // amount. Since refunds are capped to a percentage of the total // transaction's gas, it is best to keep them low in cases like this one, to // increase the likelihood of the full refund coming into effect. uint256 private constant NOT_ENTERED = 1; uint256 private constant ENTERED = 2; uint256 private _status; /** * @dev Unauthorized reentrant call. */ error ReentrancyGuardReentrantCall(); constructor() { _status = NOT_ENTERED; } /** * @dev Prevents a contract from calling itself, directly or indirectly. * Calling a `nonReentrant` function from another `nonReentrant` * function is not supported. It is possible to prevent this from happening * by making the `nonReentrant` function external, and making it call a * `private` function that does the actual work. */ modifier nonReentrant() { _nonReentrantBefore(); _; _nonReentrantAfter(); } function _nonReentrantBefore() private { // On the first call to nonReentrant, _status will be NOT_ENTERED if (_status == ENTERED) { revert ReentrancyGuardReentrantCall(); } // Any calls to nonReentrant after this point will fail _status = ENTERED; } function _nonReentrantAfter() private { // By storing the original value once again, a refund is triggered (see // https://eips.ethereum.org/EIPS/eip-2200) _status = NOT_ENTERED; } /** * @dev Returns true if the reentrancy guard is currently set to "entered", which indicates there is a * `nonReentrant` function in the call stack. */ function _reentrancyGuardEntered() internal view returns (bool) { return _status == ENTERED; } } // lib/openzeppelin-contracts/contracts/utils/math/SafeCast.sol // OpenZeppelin Contracts (last updated v5.1.0) (utils/math/SafeCast.sol) // This file was procedurally generated from scripts/generate/templates/SafeCast.js. /** * @dev Wrappers over Solidity's uintXX/intXX/bool casting operators with added overflow * checks. * * Downcasting from uint256/int256 in Solidity does not revert on overflow. This can * easily result in undesired exploitation or bugs, since developers usually * assume that overflows raise errors. `SafeCast` restores this intuition by * reverting the transaction when such an operation overflows. * * Using this library instead of the unchecked operations eliminates an entire * class of bugs, so it's recommended to use it always. */ library SafeCast { /** * @dev Value doesn't fit in an uint of `bits` size. */ error SafeCastOverflowedUintDowncast(uint8 bits, uint256 value); /** * @dev An int value doesn't fit in an uint of `bits` size. */ error SafeCastOverflowedIntToUint(int256 value); /** * @dev Value doesn't fit in an int of `bits` size. */ error SafeCastOverflowedIntDowncast(uint8 bits, int256 value); /** * @dev An uint value doesn't fit in an int of `bits` size. */ error SafeCastOverflowedUintToInt(uint256 value); /** * @dev Returns the downcasted uint248 from uint256, reverting on * overflow (when the input is greater than largest uint248). * * Counterpart to Solidity's `uint248` operator. * * Requirements: * * - input must fit into 248 bits */ function toUint248(uint256 value) internal pure returns (uint248) { if (value > type(uint248).max) { revert SafeCastOverflowedUintDowncast(248, value); } return uint248(value); } /** * @dev Returns the downcasted uint240 from uint256, reverting on * overflow (when the input is greater than largest uint240). * * Counterpart to Solidity's `uint240` operator. * * Requirements: * * - input must fit into 240 bits */ function toUint240(uint256 value) internal pure returns (uint240) { if (value > type(uint240).max) { revert SafeCastOverflowedUintDowncast(240, value); } return uint240(value); } /** * @dev Returns the downcasted uint232 from uint256, reverting on * overflow (when the input is greater than largest uint232). * * Counterpart to Solidity's `uint232` operator. * * Requirements: * * - input must fit into 232 bits */ function toUint232(uint256 value) internal pure returns (uint232) { if (value > type(uint232).max) { revert SafeCastOverflowedUintDowncast(232, value); } return uint232(value); } /** * @dev Returns the downcasted uint224 from uint256, reverting on * overflow (when the input is greater than largest uint224). * * Counterpart to Solidity's `uint224` operator. * * Requirements: * * - input must fit into 224 bits */ function toUint224(uint256 value) internal pure returns (uint224) { if (value > type(uint224).max) { revert SafeCastOverflowedUintDowncast(224, value); } return uint224(value); } /** * @dev Returns the downcasted uint216 from uint256, reverting on * overflow (when the input is greater than largest uint216). * * Counterpart to Solidity's `uint216` operator. * * Requirements: * * - input must fit into 216 bits */ function toUint216(uint256 value) internal pure returns (uint216) { if (value > type(uint216).max) { revert SafeCastOverflowedUintDowncast(216, value); } return uint216(value); } /** * @dev Returns the downcasted uint208 from uint256, reverting on * overflow (when the input is greater than largest uint208). * * Counterpart to Solidity's `uint208` operator. * * Requirements: * * - input must fit into 208 bits */ function toUint208(uint256 value) internal pure returns (uint208) { if (value > type(uint208).max) { revert SafeCastOverflowedUintDowncast(208, value); } return uint208(value); } /** * @dev Returns the downcasted uint200 from uint256, reverting on * overflow (when the input is greater than largest uint200). * * Counterpart to Solidity's `uint200` operator. * * Requirements: * * - input must fit into 200 bits */ function toUint200(uint256 value) internal pure returns (uint200) { if (value > type(uint200).max) { revert SafeCastOverflowedUintDowncast(200, value); } return uint200(value); } /** * @dev Returns the downcasted uint192 from uint256, reverting on * overflow (when the input is greater than largest uint192). * * Counterpart to Solidity's `uint192` operator. * * Requirements: * * - input must fit into 192 bits */ function toUint192(uint256 value) internal pure returns (uint192) { if (value > type(uint192).max) { revert SafeCastOverflowedUintDowncast(192, value); } return uint192(value); } /** * @dev Returns the downcasted uint184 from uint256, reverting on * overflow (when the input is greater than largest uint184). * * Counterpart to Solidity's `uint184` operator. * * Requirements: * * - input must fit into 184 bits */ function toUint184(uint256 value) internal pure returns (uint184) { if (value > type(uint184).max) { revert SafeCastOverflowedUintDowncast(184, value); } return uint184(value); } /** * @dev Returns the downcasted uint176 from uint256, reverting on * overflow (when the input is greater than largest uint176). * * Counterpart to Solidity's `uint176` operator. * * Requirements: * * - input must fit into 176 bits */ function toUint176(uint256 value) internal pure returns (uint176) { if (value > type(uint176).max) { revert SafeCastOverflowedUintDowncast(176, value); } return uint176(value); } /** * @dev Returns the downcasted uint168 from uint256, reverting on * overflow (when the input is greater than largest uint168). * * Counterpart to Solidity's `uint168` operator. * * Requirements: * * - input must fit into 168 bits */ function toUint168(uint256 value) internal pure returns (uint168) { if (value > type(uint168).max) { revert SafeCastOverflowedUintDowncast(168, value); } return uint168(value); } /** * @dev Returns the downcasted uint160 from uint256, reverting on * overflow (when the input is greater than largest uint160). * * Counterpart to Solidity's `uint160` operator. * * Requirements: * * - input must fit into 160 bits */ function toUint160(uint256 value) internal pure returns (uint160) { if (value > type(uint160).max) { revert SafeCastOverflowedUintDowncast(160, value); } return uint160(value); } /** * @dev Returns the downcasted uint152 from uint256, reverting on * overflow (when the input is greater than largest uint152). * * Counterpart to Solidity's `uint152` operator. * * Requirements: * * - input must fit into 152 bits */ function toUint152(uint256 value) internal pure returns (uint152) { if (value > type(uint152).max) { revert SafeCastOverflowedUintDowncast(152, value); } return uint152(value); } /** * @dev Returns the downcasted uint144 from uint256, reverting on * overflow (when the input is greater than largest uint144). * * Counterpart to Solidity's `uint144` operator. * * Requirements: * * - input must fit into 144 bits */ function toUint144(uint256 value) internal pure returns (uint144) { if (value > type(uint144).max) { revert SafeCastOverflowedUintDowncast(144, value); } return uint144(value); } /** * @dev Returns the downcasted uint136 from uint256, reverting on * overflow (when the input is greater than largest uint136). * * Counterpart to Solidity's `uint136` operator. * * Requirements: * * - input must fit into 136 bits */ function toUint136(uint256 value) internal pure returns (uint136) { if (value > type(uint136).max) { revert SafeCastOverflowedUintDowncast(136, value); } return uint136(value); } /** * @dev Returns the downcasted uint128 from uint256, reverting on * overflow (when the input is greater than largest uint128). * * Counterpart to Solidity's `uint128` operator. * * Requirements: * * - input must fit into 128 bits */ function toUint128(uint256 value) internal pure returns (uint128) { if (value > type(uint128).max) { revert SafeCastOverflowedUintDowncast(128, value); } return uint128(value); } /** * @dev Returns the downcasted uint120 from uint256, reverting on * overflow (when the input is greater than largest uint120). * * Counterpart to Solidity's `uint120` operator. * * Requirements: * * - input must fit into 120 bits */ function toUint120(uint256 value) internal pure returns (uint120) { if (value > type(uint120).max) { revert SafeCastOverflowedUintDowncast(120, value); } return uint120(value); } /** * @dev Returns the downcasted uint112 from uint256, reverting on * overflow (when the input is greater than largest uint112). * * Counterpart to Solidity's `uint112` operator. * * Requirements: * * - input must fit into 112 bits */ function toUint112(uint256 value) internal pure returns (uint112) { if (value > type(uint112).max) { revert SafeCastOverflowedUintDowncast(112, value); } return uint112(value); } /** * @dev Returns the downcasted uint104 from uint256, reverting on * overflow (when the input is greater than largest uint104). * * Counterpart to Solidity's `uint104` operator. * * Requirements: * * - input must fit into 104 bits */ function toUint104(uint256 value) internal pure returns (uint104) { if (value > type(uint104).max) { revert SafeCastOverflowedUintDowncast(104, value); } return uint104(value); } /** * @dev Returns the downcasted uint96 from uint256, reverting on * overflow (when the input is greater than largest uint96). * * Counterpart to Solidity's `uint96` operator. * * Requirements: * * - input must fit into 96 bits */ function toUint96(uint256 value) internal pure returns (uint96) { if (value > type(uint96).max) { revert SafeCastOverflowedUintDowncast(96, value); } return uint96(value); } /** * @dev Returns the downcasted uint88 from uint256, reverting on * overflow (when the input is greater than largest uint88). * * Counterpart to Solidity's `uint88` operator. * * Requirements: * * - input must fit into 88 bits */ function toUint88(uint256 value) internal pure returns (uint88) { if (value > type(uint88).max) { revert SafeCastOverflowedUintDowncast(88, value); } return uint88(value); } /** * @dev Returns the downcasted uint80 from uint256, reverting on * overflow (when the input is greater than largest uint80). * * Counterpart to Solidity's `uint80` operator. * * Requirements: * * - input must fit into 80 bits */ function toUint80(uint256 value) internal pure returns (uint80) { if (value > type(uint80).max) { revert SafeCastOverflowedUintDowncast(80, value); } return uint80(value); } /** * @dev Returns the downcasted uint72 from uint256, reverting on * overflow (when the input is greater than largest uint72). * * Counterpart to Solidity's `uint72` operator. * * Requirements: * * - input must fit into 72 bits */ function toUint72(uint256 value) internal pure returns (uint72) { if (value > type(uint72).max) { revert SafeCastOverflowedUintDowncast(72, value); } return uint72(value); } /** * @dev Returns the downcasted uint64 from uint256, reverting on * overflow (when the input is greater than largest uint64). * * Counterpart to Solidity's `uint64` operator. * * Requirements: * * - input must fit into 64 bits */ function toUint64(uint256 value) internal pure returns (uint64) { if (value > type(uint64).max) { revert SafeCastOverflowedUintDowncast(64, value); } return uint64(value); } /** * @dev Returns the downcasted uint56 from uint256, reverting on * overflow (when the input is greater than largest uint56). * * Counterpart to Solidity's `uint56` operator. * * Requirements: * * - input must fit into 56 bits */ function toUint56(uint256 value) internal pure returns (uint56) { if (value > type(uint56).max) { revert SafeCastOverflowedUintDowncast(56, value); } return uint56(value); } /** * @dev Returns the downcasted uint48 from uint256, reverting on * overflow (when the input is greater than largest uint48). * * Counterpart to Solidity's `uint48` operator. * * Requirements: * * - input must fit into 48 bits */ function toUint48(uint256 value) internal pure returns (uint48) { if (value > type(uint48).max) { revert SafeCastOverflowedUintDowncast(48, value); } return uint48(value); } /** * @dev Returns the downcasted uint40 from uint256, reverting on * overflow (when the input is greater than largest uint40). * * Counterpart to Solidity's `uint40` operator. * * Requirements: * * - input must fit into 40 bits */ function toUint40(uint256 value) internal pure returns (uint40) { if (value > type(uint40).max) { revert SafeCastOverflowedUintDowncast(40, value); } return uint40(value); } /** * @dev Returns the downcasted uint32 from uint256, reverting on * overflow (when the input is greater than largest uint32). * * Counterpart to Solidity's `uint32` operator. * * Requirements: * * - input must fit into 32 bits */ function toUint32(uint256 value) internal pure returns (uint32) { if (value > type(uint32).max) { revert SafeCastOverflowedUintDowncast(32, value); } return uint32(value); } /** * @dev Returns the downcasted uint24 from uint256, reverting on * overflow (when the input is greater than largest uint24). * * Counterpart to Solidity's `uint24` operator. * * Requirements: * * - input must fit into 24 bits */ function toUint24(uint256 value) internal pure returns (uint24) { if (value > type(uint24).max) { revert SafeCastOverflowedUintDowncast(24, value); } return uint24(value); } /** * @dev Returns the downcasted uint16 from uint256, reverting on * overflow (when the input is greater than largest uint16). * * Counterpart to Solidity's `uint16` operator. * * Requirements: * * - input must fit into 16 bits */ function toUint16(uint256 value) internal pure returns (uint16) { if (value > type(uint16).max) { revert SafeCastOverflowedUintDowncast(16, value); } return uint16(value); } /** * @dev Returns the downcasted uint8 from uint256, reverting on * overflow (when the input is greater than largest uint8). * * Counterpart to Solidity's `uint8` operator. * * Requirements: * * - input must fit into 8 bits */ function toUint8(uint256 value) internal pure returns (uint8) { if (value > type(uint8).max) { revert SafeCastOverflowedUintDowncast(8, value); } return uint8(value); } /** * @dev Converts a signed int256 into an unsigned uint256. * * Requirements: * * - input must be greater than or equal to 0. */ function toUint256(int256 value) internal pure returns (uint256) { if (value < 0) { revert SafeCastOverflowedIntToUint(value); } return uint256(value); } /** * @dev Returns the downcasted int248 from int256, reverting on * overflow (when the input is less than smallest int248 or * greater than largest int248). * * Counterpart to Solidity's `int248` operator. * * Requirements: * * - input must fit into 248 bits */ function toInt248(int256 value) internal pure returns (int248 downcasted) { downcasted = int248(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(248, value); } } /** * @dev Returns the downcasted int240 from int256, reverting on * overflow (when the input is less than smallest int240 or * greater than largest int240). * * Counterpart to Solidity's `int240` operator. * * Requirements: * * - input must fit into 240 bits */ function toInt240(int256 value) internal pure returns (int240 downcasted) { downcasted = int240(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(240, value); } } /** * @dev Returns the downcasted int232 from int256, reverting on * overflow (when the input is less than smallest int232 or * greater than largest int232). * * Counterpart to Solidity's `int232` operator. * * Requirements: * * - input must fit into 232 bits */ function toInt232(int256 value) internal pure returns (int232 downcasted) { downcasted = int232(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(232, value); } } /** * @dev Returns the downcasted int224 from int256, reverting on * overflow (when the input is less than smallest int224 or * greater than largest int224). * * Counterpart to Solidity's `int224` operator. * * Requirements: * * - input must fit into 224 bits */ function toInt224(int256 value) internal pure returns (int224 downcasted) { downcasted = int224(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(224, value); } } /** * @dev Returns the downcasted int216 from int256, reverting on * overflow (when the input is less than smallest int216 or * greater than largest int216). * * Counterpart to Solidity's `int216` operator. * * Requirements: * * - input must fit into 216 bits */ function toInt216(int256 value) internal pure returns (int216 downcasted) { downcasted = int216(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(216, value); } } /** * @dev Returns the downcasted int208 from int256, reverting on * overflow (when the input is less than smallest int208 or * greater than largest int208). * * Counterpart to Solidity's `int208` operator. * * Requirements: * * - input must fit into 208 bits */ function toInt208(int256 value) internal pure returns (int208 downcasted) { downcasted = int208(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(208, value); } } /** * @dev Returns the downcasted int200 from int256, reverting on * overflow (when the input is less than smallest int200 or * greater than largest int200). * * Counterpart to Solidity's `int200` operator. * * Requirements: * * - input must fit into 200 bits */ function toInt200(int256 value) internal pure returns (int200 downcasted) { downcasted = int200(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(200, value); } } /** * @dev Returns the downcasted int192 from int256, reverting on * overflow (when the input is less than smallest int192 or * greater than largest int192). * * Counterpart to Solidity's `int192` operator. * * Requirements: * * - input must fit into 192 bits */ function toInt192(int256 value) internal pure returns (int192 downcasted) { downcasted = int192(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(192, value); } } /** * @dev Returns the downcasted int184 from int256, reverting on * overflow (when the input is less than smallest int184 or * greater than largest int184). * * Counterpart to Solidity's `int184` operator. * * Requirements: * * - input must fit into 184 bits */ function toInt184(int256 value) internal pure returns (int184 downcasted) { downcasted = int184(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(184, value); } } /** * @dev Returns the downcasted int176 from int256, reverting on * overflow (when the input is less than smallest int176 or * greater than largest int176). * * Counterpart to Solidity's `int176` operator. * * Requirements: * * - input must fit into 176 bits */ function toInt176(int256 value) internal pure returns (int176 downcasted) { downcasted = int176(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(176, value); } } /** * @dev Returns the downcasted int168 from int256, reverting on * overflow (when the input is less than smallest int168 or * greater than largest int168). * * Counterpart to Solidity's `int168` operator. * * Requirements: * * - input must fit into 168 bits */ function toInt168(int256 value) internal pure returns (int168 downcasted) { downcasted = int168(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(168, value); } } /** * @dev Returns the downcasted int160 from int256, reverting on * overflow (when the input is less than smallest int160 or * greater than largest int160). * * Counterpart to Solidity's `int160` operator. * * Requirements: * * - input must fit into 160 bits */ function toInt160(int256 value) internal pure returns (int160 downcasted) { downcasted = int160(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(160, value); } } /** * @dev Returns the downcasted int152 from int256, reverting on * overflow (when the input is less than smallest int152 or * greater than largest int152). * * Counterpart to Solidity's `int152` operator. * * Requirements: * * - input must fit into 152 bits */ function toInt152(int256 value) internal pure returns (int152 downcasted) { downcasted = int152(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(152, value); } } /** * @dev Returns the downcasted int144 from int256, reverting on * overflow (when the input is less than smallest int144 or * greater than largest int144). * * Counterpart to Solidity's `int144` operator. * * Requirements: * * - input must fit into 144 bits */ function toInt144(int256 value) internal pure returns (int144 downcasted) { downcasted = int144(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(144, value); } } /** * @dev Returns the downcasted int136 from int256, reverting on * overflow (when the input is less than smallest int136 or * greater than largest int136). * * Counterpart to Solidity's `int136` operator. * * Requirements: * * - input must fit into 136 bits */ function toInt136(int256 value) internal pure returns (int136 downcasted) { downcasted = int136(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(136, value); } } /** * @dev Returns the downcasted int128 from int256, reverting on * overflow (when the input is less than smallest int128 or * greater than largest int128). * * Counterpart to Solidity's `int128` operator. * * Requirements: * * - input must fit into 128 bits */ function toInt128(int256 value) internal pure returns (int128 downcasted) { downcasted = int128(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(128, value); } } /** * @dev Returns the downcasted int120 from int256, reverting on * overflow (when the input is less than smallest int120 or * greater than largest int120). * * Counterpart to Solidity's `int120` operator. * * Requirements: * * - input must fit into 120 bits */ function toInt120(int256 value) internal pure returns (int120 downcasted) { downcasted = int120(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(120, value); } } /** * @dev Returns the downcasted int112 from int256, reverting on * overflow (when the input is less than smallest int112 or * greater than largest int112). * * Counterpart to Solidity's `int112` operator. * * Requirements: * * - input must fit into 112 bits */ function toInt112(int256 value) internal pure returns (int112 downcasted) { downcasted = int112(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(112, value); } } /** * @dev Returns the downcasted int104 from int256, reverting on * overflow (when the input is less than smallest int104 or * greater than largest int104). * * Counterpart to Solidity's `int104` operator. * * Requirements: * * - input must fit into 104 bits */ function toInt104(int256 value) internal pure returns (int104 downcasted) { downcasted = int104(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(104, value); } } /** * @dev Returns the downcasted int96 from int256, reverting on * overflow (when the input is less than smallest int96 or * greater than largest int96). * * Counterpart to Solidity's `int96` operator. * * Requirements: * * - input must fit into 96 bits */ function toInt96(int256 value) internal pure returns (int96 downcasted) { downcasted = int96(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(96, value); } } /** * @dev Returns the downcasted int88 from int256, reverting on * overflow (when the input is less than smallest int88 or * greater than largest int88). * * Counterpart to Solidity's `int88` operator. * * Requirements: * * - input must fit into 88 bits */ function toInt88(int256 value) internal pure returns (int88 downcasted) { downcasted = int88(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(88, value); } } /** * @dev Returns the downcasted int80 from int256, reverting on * overflow (when the input is less than smallest int80 or * greater than largest int80). * * Counterpart to Solidity's `int80` operator. * * Requirements: * * - input must fit into 80 bits */ function toInt80(int256 value) internal pure returns (int80 downcasted) { downcasted = int80(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(80, value); } } /** * @dev Returns the downcasted int72 from int256, reverting on * overflow (when the input is less than smallest int72 or * greater than largest int72). * * Counterpart to Solidity's `int72` operator. * * Requirements: * * - input must fit into 72 bits */ function toInt72(int256 value) internal pure returns (int72 downcasted) { downcasted = int72(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(72, value); } } /** * @dev Returns the downcasted int64 from int256, reverting on * overflow (when the input is less than smallest int64 or * greater than largest int64). * * Counterpart to Solidity's `int64` operator. * * Requirements: * * - input must fit into 64 bits */ function toInt64(int256 value) internal pure returns (int64 downcasted) { downcasted = int64(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(64, value); } } /** * @dev Returns the downcasted int56 from int256, reverting on * overflow (when the input is less than smallest int56 or * greater than largest int56). * * Counterpart to Solidity's `int56` operator. * * Requirements: * * - input must fit into 56 bits */ function toInt56(int256 value) internal pure returns (int56 downcasted) { downcasted = int56(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(56, value); } } /** * @dev Returns the downcasted int48 from int256, reverting on * overflow (when the input is less than smallest int48 or * greater than largest int48). * * Counterpart to Solidity's `int48` operator. * * Requirements: * * - input must fit into 48 bits */ function toInt48(int256 value) internal pure returns (int48 downcasted) { downcasted = int48(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(48, value); } } /** * @dev Returns the downcasted int40 from int256, reverting on * overflow (when the input is less than smallest int40 or * greater than largest int40). * * Counterpart to Solidity's `int40` operator. * * Requirements: * * - input must fit into 40 bits */ function toInt40(int256 value) internal pure returns (int40 downcasted) { downcasted = int40(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(40, value); } } /** * @dev Returns the downcasted int32 from int256, reverting on * overflow (when the input is less than smallest int32 or * greater than largest int32). * * Counterpart to Solidity's `int32` operator. * * Requirements: * * - input must fit into 32 bits */ function toInt32(int256 value) internal pure returns (int32 downcasted) { downcasted = int32(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(32, value); } } /** * @dev Returns the downcasted int24 from int256, reverting on * overflow (when the input is less than smallest int24 or * greater than largest int24). * * Counterpart to Solidity's `int24` operator. * * Requirements: * * - input must fit into 24 bits */ function toInt24(int256 value) internal pure returns (int24 downcasted) { downcasted = int24(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(24, value); } } /** * @dev Returns the downcasted int16 from int256, reverting on * overflow (when the input is less than smallest int16 or * greater than largest int16). * * Counterpart to Solidity's `int16` operator. * * Requirements: * * - input must fit into 16 bits */ function toInt16(int256 value) internal pure returns (int16 downcasted) { downcasted = int16(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(16, value); } } /** * @dev Returns the downcasted int8 from int256, reverting on * overflow (when the input is less than smallest int8 or * greater than largest int8). * * Counterpart to Solidity's `int8` operator. * * Requirements: * * - input must fit into 8 bits */ function toInt8(int256 value) internal pure returns (int8 downcasted) { downcasted = int8(value); if (downcasted != value) { revert SafeCastOverflowedIntDowncast(8, value); } } /** * @dev Converts an unsigned uint256 into a signed int256. * * Requirements: * * - input must be less than or equal to maxInt256. */ function toInt256(uint256 value) internal pure returns (int256) { // Note: Unsafe cast below is okay because `type(int256).max` is guaranteed to be positive if (value > uint256(type(int256).max)) { revert SafeCastOverflowedUintToInt(value); } return int256(value); } /** * @dev Cast a boolean (false or true) to a uint256 (0 or 1) with no jump. */ function toUint(bool b) internal pure returns (uint256 u) { assembly ("memory-safe") { u := iszero(iszero(b)) } } } // lib/openzeppelin-contracts/contracts/utils/Address.sol // OpenZeppelin Contracts (last updated v5.1.0) (utils/Address.sol) /** * @dev Collection of functions related to the address type */ library Address { /** * @dev There's no code at `target` (it is not a contract). */ error AddressEmptyCode(address target); /** * @dev Replacement for Solidity's `transfer`: sends `amount` wei to * `recipient`, forwarding all available gas and reverting on errors. * * https://eips.ethereum.org/EIPS/eip-1884[EIP1884] increases the gas cost * of certain opcodes, possibly making contracts go over the 2300 gas limit * imposed by `transfer`, making them unable to receive funds via * `transfer`. {sendValue} removes this limitation. * * https://consensys.net/diligence/blog/2019/09/stop-using-soliditys-transfer-now/[Learn more]. * * IMPORTANT: because control is transferred to `recipient`, care must be * taken to not create reentrancy vulnerabilities. Consider using * {ReentrancyGuard} or the * https://solidity.readthedocs.io/en/v0.8.20/security-considerations.html#use-the-checks-effects-interactions-pattern[checks-effects-interactions pattern]. */ function sendValue(address payable recipient, uint256 amount) internal { if (address(this).balance < amount) { revert Errors.InsufficientBalance(address(this).balance, amount); } (bool success, ) = recipient.call{value: amount}(""); if (!success) { revert Errors.FailedCall(); } } /** * @dev Performs a Solidity function call using a low level `call`. A * plain `call` is an unsafe replacement for a function call: use this * function instead. * * If `target` reverts with a revert reason or custom error, it is bubbled * up by this function (like regular Solidity function calls). However, if * the call reverted with no returned reason, this function reverts with a * {Errors.FailedCall} error. * * Returns the raw returned data. To convert to the expected return value, * use https://solidity.readthedocs.io/en/latest/units-and-global-variables.html?highlight=abi.decode#abi-encoding-and-decoding-functions[`abi.decode`]. * * Requirements: * * - `target` must be a contract. * - calling `target` with `data` must not revert. */ function functionCall(address target, bytes memory data) internal returns (bytes memory) { return functionCallWithValue(target, data, 0); } /** * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`], * but also transferring `value` wei to `target`. * * Requirements: * * - the calling contract must have an ETH balance of at least `value`. * - the called Solidity function must be `payable`. */ function functionCallWithValue(address target, bytes memory data, uint256 value) internal returns (bytes memory) { if (address(this).balance < value) { revert Errors.InsufficientBalance(address(this).balance, value); } (bool success, bytes memory returndata) = target.call{value: value}(data); return verifyCallResultFromTarget(target, success, returndata); } /** * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`], * but performing a static call. */ function functionStaticCall(address target, bytes memory data) internal view returns (bytes memory) { (bool success, bytes memory returndata) = target.staticcall(data); return verifyCallResultFromTarget(target, success, returndata); } /** * @dev Same as {xref-Address-functionCall-address-bytes-}[`functionCall`], * but performing a delegate call. */ function functionDelegateCall(address target, bytes memory data) internal returns (bytes memory) { (bool success, bytes memory returndata) = target.delegatecall(data); return verifyCallResultFromTarget(target, success, returndata); } /** * @dev Tool to verify that a low level call to smart-contract was successful, and reverts if the target * was not a contract or bubbling up the revert reason (falling back to {Errors.FailedCall}) in case * of an unsuccessful call. */ function verifyCallResultFromTarget( address target, bool success, bytes memory returndata ) internal view returns (bytes memory) { if (!success) { _revert(returndata); } else { // only check if target is a contract if the call was successful and the return data is empty // otherwise we already know that it was a contract if (returndata.length == 0 && target.code.length == 0) { revert AddressEmptyCode(target); } return returndata; } } /** * @dev Tool to verify that a low level call was successful, and reverts if it wasn't, either by bubbling the * revert reason or with a default {Errors.FailedCall} error. */ function verifyCallResult(bool success, bytes memory returndata) internal pure returns (bytes memory) { if (!success) { _revert(returndata); } else { return returndata; } } /** * @dev Reverts with returndata if present. Otherwise reverts with {Errors.FailedCall}. */ function _revert(bytes memory returndata) private pure { // Look for revert reason and bubble it up if present if (returndata.length > 0) { // The easiest way to bubble the revert reason is using memory via assembly assembly ("memory-safe") { let returndata_size := mload(returndata) revert(add(32, returndata), returndata_size) } } else { revert Errors.FailedCall(); } } } // lib/openzeppelin-contracts/contracts/interfaces/IERC165.sol // OpenZeppelin Contracts (last updated v5.0.0) (interfaces/IERC165.sol) // lib/openzeppelin-contracts/contracts/interfaces/IERC20.sol // OpenZeppelin Contracts (last updated v5.0.0) (interfaces/IERC20.sol) // lib/openzeppelin-contracts/contracts/access/Ownable.sol // OpenZeppelin Contracts (last updated v5.0.0) (access/Ownable.sol) /** * @dev Contract module which provides a basic access control mechanism, where * there is an account (an owner) that can be granted exclusive access to * specific functions. * * The initial owner is set to the address provided by the deployer. This can * later be changed with {transferOwnership}. * * This module is used through inheritance. It will make available the modifier * `onlyOwner`, which can be applied to your functions to restrict their use to * the owner. */ abstract contract Ownable is Context { address private _owner; /** * @dev The caller account is not authorized to perform an operation. */ error OwnableUnauthorizedAccount(address account); /** * @dev The owner is not a valid owner account. (eg. `address(0)`) */ error OwnableInvalidOwner(address owner); event OwnershipTransferred(address indexed previousOwner, address indexed newOwner); /** * @dev Initializes the contract setting the address provided by the deployer as the initial owner. */ constructor(address initialOwner) { if (initialOwner == address(0)) { revert OwnableInvalidOwner(address(0)); } _transferOwnership(initialOwner); } /** * @dev Throws if called by any account other than the owner. */ modifier onlyOwner() { _checkOwner(); _; } /** * @dev Returns the address of the current owner. */ function owner() public view virtual returns (address) { return _owner; } /** * @dev Throws if the sender is not the owner. */ function _checkOwner() internal view virtual { if (owner() != _msgSender()) { revert OwnableUnauthorizedAccount(_msgSender()); } } /** * @dev Leaves the contract without owner. It will not be possible to call * `onlyOwner` functions. Can only be called by the current owner. * * NOTE: Renouncing ownership will leave the contract without an owner, * thereby disabling any functionality that is only available to the owner. */ function renounceOwnership() public virtual onlyOwner { _transferOwnership(address(0)); } /** * @dev Transfers ownership of the contract to a new account (`newOwner`). * Can only be called by the current owner. */ function transferOwnership(address newOwner) public virtual onlyOwner { if (newOwner == address(0)) { revert OwnableInvalidOwner(address(0)); } _transferOwnership(newOwner); } /** * @dev Transfers ownership of the contract to a new account (`newOwner`). * Internal function without access restriction. */ function _transferOwnership(address newOwner) internal virtual { address oldOwner = _owner; _owner = newOwner; emit OwnershipTransferred(oldOwner, newOwner); } } // lib/openzeppelin-contracts/contracts/utils/math/Math.sol // OpenZeppelin Contracts (last updated v5.1.0) (utils/math/Math.sol) /** * @dev Standard math utilities missing in the Solidity language. */ library Math { enum Rounding { Floor, // Toward negative infinity Ceil, // Toward positive infinity Trunc, // Toward zero Expand // Away from zero } /** * @dev Returns the addition of two unsigned integers, with an success flag (no overflow). */ function tryAdd(uint256 a, uint256 b) internal pure returns (bool success, uint256 result) { unchecked { uint256 c = a + b; if (c < a) return (false, 0); return (true, c); } } /** * @dev Returns the subtraction of two unsigned integers, with an success flag (no overflow). */ function trySub(uint256 a, uint256 b) internal pure returns (bool success, uint256 result) { unchecked { if (b > a) return (false, 0); return (true, a - b); } } /** * @dev Returns the multiplication of two unsigned integers, with an success flag (no overflow). */ function tryMul(uint256 a, uint256 b) internal pure returns (bool success, uint256 result) { unchecked { // Gas optimization: this is cheaper than requiring 'a' not being zero, but the // benefit is lost if 'b' is also tested. // See: https://github.com/OpenZeppelin/openzeppelin-contracts/pull/522 if (a == 0) return (true, 0); uint256 c = a * b; if (c / a != b) return (false, 0); return (true, c); } } /** * @dev Returns the division of two unsigned integers, with a success flag (no division by zero). */ function tryDiv(uint256 a, uint256 b) internal pure returns (bool success, uint256 result) { unchecked { if (b == 0) return (false, 0); return (true, a / b); } } /** * @dev Returns the remainder of dividing two unsigned integers, with a success flag (no division by zero). */ function tryMod(uint256 a, uint256 b) internal pure returns (bool success, uint256 result) { unchecked { if (b == 0) return (false, 0); return (true, a % b); } } /** * @dev Branchless ternary evaluation for `a ? b : c`. Gas costs are constant. * * IMPORTANT: This function may reduce bytecode size and consume less gas when used standalone. * However, the compiler may optimize Solidity ternary operations (i.e. `a ? b : c`) to only compute * one branch when needed, making this function more expensive. */ function ternary(bool condition, uint256 a, uint256 b) internal pure returns (uint256) { unchecked { // branchless ternary works because: // b ^ (a ^ b) == a // b ^ 0 == b return b ^ ((a ^ b) * SafeCast.toUint(condition)); } } /** * @dev Returns the largest of two numbers. */ function max(uint256 a, uint256 b) internal pure returns (uint256) { return ternary(a > b, a, b); } /** * @dev Returns the smallest of two numbers. */ function min(uint256 a, uint256 b) internal pure returns (uint256) { return ternary(a < b, a, b); } /** * @dev Returns the average of two numbers. The result is rounded towards * zero. */ function average(uint256 a, uint256 b) internal pure returns (uint256) { // (a + b) / 2 can overflow. return (a & b) + (a ^ b) / 2; } /** * @dev Returns the ceiling of the division of two numbers. * * This differs from standard division with `/` in that it rounds towards infinity instead * of rounding towards zero. */ function ceilDiv(uint256 a, uint256 b) internal pure returns (uint256) { if (b == 0) { // Guarantee the same behavior as in a regular Solidity division. Panic.panic(Panic.DIVISION_BY_ZERO); } // The following calculation ensures accurate ceiling division without overflow. // Since a is non-zero, (a - 1) / b will not overflow. // The largest possible result occurs when (a - 1) / b is type(uint256).max, // but the largest value we can obtain is type(uint256).max - 1, which happens // when a = type(uint256).max and b = 1. unchecked { return SafeCast.toUint(a > 0) * ((a - 1) / b + 1); } } /** * @dev Calculates floor(x * y / denominator) with full precision. Throws if result overflows a uint256 or * denominator == 0. * * Original credit to Remco Bloemen under MIT license (https://xn--2-umb.com/21/muldiv) with further edits by * Uniswap Labs also under MIT license. */ function mulDiv(uint256 x, uint256 y, uint256 denominator) internal pure returns (uint256 result) { unchecked { // 512-bit multiply [prod1 prod0] = x * y. Compute the product mod 2²⁵⁶ and mod 2²⁵⁶ - 1, then use // the Chinese Remainder Theorem to reconstruct the 512 bit result. The result is stored in two 256 // variables such that product = prod1 * 2²⁵⁶ + prod0. uint256 prod0 = x * y; // Least significant 256 bits of the product uint256 prod1; // Most significant 256 bits of the product assembly { let mm := mulmod(x, y, not(0)) prod1 := sub(sub(mm, prod0), lt(mm, prod0)) } // Handle non-overflow cases, 256 by 256 division. if (prod1 == 0) { // Solidity will revert if denominator == 0, unlike the div opcode on its own. // The surrounding unchecked block does not change this fact. // See https://docs.soliditylang.org/en/latest/control-structures.html#checked-or-unchecked-arithmetic. return prod0 / denominator; } // Make sure the result is less than 2²⁵⁶. Also prevents denominator == 0. if (denominator <= prod1) { Panic.panic(ternary(denominator == 0, Panic.DIVISION_BY_ZERO, Panic.UNDER_OVERFLOW)); } /////////////////////////////////////////////// // 512 by 256 division. /////////////////////////////////////////////// // Make division exact by subtracting the remainder from [prod1 prod0]. uint256 remainder; assembly { // Compute remainder using mulmod. remainder := mulmod(x, y, denominator) // Subtract 256 bit number from 512 bit number. prod1 := sub(prod1, gt(remainder, prod0)) prod0 := sub(prod0, remainder) } // Factor powers of two out of denominator and compute largest power of two divisor of denominator. // Always >= 1. See https://cs.stackexchange.com/q/138556/92363. uint256 twos = denominator & (0 - denominator); assembly { // Divide denominator by twos. denominator := div(denominator, twos) // Divide [prod1 prod0] by twos. prod0 := div(prod0, twos) // Flip twos such that it is 2²⁵⁶ / twos. If twos is zero, then it becomes one. twos := add(div(sub(0, twos), twos), 1) } // Shift in bits from prod1 into prod0. prod0 |= prod1 * twos; // Invert denominator mod 2²⁵⁶. Now that denominator is an odd number, it has an inverse modulo 2²⁵⁶ such // that denominator * inv ≡ 1 mod 2²⁵⁶. Compute the inverse by starting with a seed that is correct for // four bits. That is, denominator * inv ≡ 1 mod 2⁴. uint256 inverse = (3 * denominator) ^ 2; // Use the Newton-Raphson iteration to improve the precision. Thanks to Hensel's lifting lemma, this also // works in modular arithmetic, doubling the correct bits in each step. inverse *= 2 - denominator * inverse; // inverse mod 2⁸ inverse *= 2 - denominator * inverse; // inverse mod 2¹⁶ inverse *= 2 - denominator * inverse; // inverse mod 2³² inverse *= 2 - denominator * inverse; // inverse mod 2⁶⁴ inverse *= 2 - denominator * inverse; // inverse mod 2¹²⁸ inverse *= 2 - denominator * inverse; // inverse mod 2²⁵⁶ // Because the division is now exact we can divide by multiplying with the modular inverse of denominator. // This will give us the correct result modulo 2²⁵⁶. Since the preconditions guarantee that the outcome is // less than 2²⁵⁶, this is the final result. We don't need to compute the high bits of the result and prod1 // is no longer required. result = prod0 * inverse; return result; } } /** * @dev Calculates x * y / denominator with full precision, following the selected rounding direction. */ function mulDiv(uint256 x, uint256 y, uint256 denominator, Rounding rounding) internal pure returns (uint256) { return mulDiv(x, y, denominator) + SafeCast.toUint(unsignedRoundsUp(rounding) && mulmod(x, y, denominator) > 0); } /** * @dev Calculate the modular multiplicative inverse of a number in Z/nZ. * * If n is a prime, then Z/nZ is a field. In that case all elements are inversible, except 0. * If n is not a prime, then Z/nZ is not a field, and some elements might not be inversible. * * If the input value is not inversible, 0 is returned. * * NOTE: If you know for sure that n is (big) a prime, it may be cheaper to use Fermat's little theorem and get the * inverse using `Math.modExp(a, n - 2, n)`. See {invModPrime}. */ function invMod(uint256 a, uint256 n) internal pure returns (uint256) { unchecked { if (n == 0) return 0; // The inverse modulo is calculated using the Extended Euclidean Algorithm (iterative version) // Used to compute integers x and y such that: ax + ny = gcd(a, n). // When the gcd is 1, then the inverse of a modulo n exists and it's x. // ax + ny = 1 // ax = 1 + (-y)n // ax ≡ 1 (mod n) # x is the inverse of a modulo n // If the remainder is 0 the gcd is n right away. uint256 remainder = a % n; uint256 gcd = n; // Therefore the initial coefficients are: // ax + ny = gcd(a, n) = n // 0a + 1n = n int256 x = 0; int256 y = 1; while (remainder != 0) { uint256 quotient = gcd / remainder; (gcd, remainder) = ( // The old remainder is the next gcd to try. remainder, // Compute the next remainder. // Can't overflow given that (a % gcd) * (gcd // (a % gcd)) <= gcd // where gcd is at most n (capped to type(uint256).max) gcd - remainder * quotient ); (x, y) = ( // Increment the coefficient of a. y, // Decrement the coefficient of n. // Can overflow, but the result is casted to uint256 so that the // next value of y is "wrapped around" to a value between 0 and n - 1. x - y * int256(quotient) ); } if (gcd != 1) return 0; // No inverse exists. return ternary(x < 0, n - uint256(-x), uint256(x)); // Wrap the result if it's negative. } } /** * @dev Variant of {invMod}. More efficient, but only works if `p` is known to be a prime greater than `2`. * * From https://en.wikipedia.org/wiki/Fermat%27s_little_theorem[Fermat's little theorem], we know that if p is * prime, then `a**(p-1) ≡ 1 mod p`. As a consequence, we have `a * a**(p-2) ≡ 1 mod p`, which means that * `a**(p-2)` is the modular multiplicative inverse of a in Fp. * * NOTE: this function does NOT check that `p` is a prime greater than `2`. */ function invModPrime(uint256 a, uint256 p) internal view returns (uint256) { unchecked { return Math.modExp(a, p - 2, p); } } /** * @dev Returns the modular exponentiation of the specified base, exponent and modulus (b ** e % m) * * Requirements: * - modulus can't be zero * - underlying staticcall to precompile must succeed * * IMPORTANT: The result is only valid if the underlying call succeeds. When using this function, make * sure the chain you're using it on supports the precompiled contract for modular exponentiation * at address 0x05 as specified in https://eips.ethereum.org/EIPS/eip-198[EIP-198]. Otherwise, * the underlying function will succeed given the lack of a revert, but the result may be incorrectly * interpreted as 0. */ function modExp(uint256 b, uint256 e, uint256 m) internal view returns (uint256) { (bool success, uint256 result) = tryModExp(b, e, m); if (!success) { Panic.panic(Panic.DIVISION_BY_ZERO); } return result; } /** * @dev Returns the modular exponentiation of the specified base, exponent and modulus (b ** e % m). * It includes a success flag indicating if the operation succeeded. Operation will be marked as failed if trying * to operate modulo 0 or if the underlying precompile reverted. * * IMPORTANT: The result is only valid if the success flag is true. When using this function, make sure the chain * you're using it on supports the precompiled contract for modular exponentiation at address 0x05 as specified in * https://eips.ethereum.org/EIPS/eip-198[EIP-198]. Otherwise, the underlying function will succeed given the lack * of a revert, but the result may be incorrectly interpreted as 0. */ function tryModExp(uint256 b, uint256 e, uint256 m) internal view returns (bool success, uint256 result) { if (m == 0) return (false, 0); assembly ("memory-safe") { let ptr := mload(0x40) // | Offset | Content | Content (Hex) | // |-----------|------------|--------------------------------------------------------------------| // | 0x00:0x1f | size of b | 0x0000000000000000000000000000000000000000000000000000000000000020 | // | 0x20:0x3f | size of e | 0x0000000000000000000000000000000000000000000000000000000000000020 | // | 0x40:0x5f | size of m | 0x0000000000000000000000000000000000000000000000000000000000000020 | // | 0x60:0x7f | value of b | 0x<.............................................................b> | // | 0x80:0x9f | value of e | 0x<.............................................................e> | // | 0xa0:0xbf | value of m | 0x<.............................................................m> | mstore(ptr, 0x20) mstore(add(ptr, 0x20), 0x20) mstore(add(ptr, 0x40), 0x20) mstore(add(ptr, 0x60), b) mstore(add(ptr, 0x80), e) mstore(add(ptr, 0xa0), m) // Given the result < m, it's guaranteed to fit in 32 bytes, // so we can use the memory scratch space located at offset 0. success := staticcall(gas(), 0x05, ptr, 0xc0, 0x00, 0x20) result := mload(0x00) } } /** * @dev Variant of {modExp} that supports inputs of arbitrary length. */ function modExp(bytes memory b, bytes memory e, bytes memory m) internal view returns (bytes memory) { (bool success, bytes memory result) = tryModExp(b, e, m); if (!success) { Panic.panic(Panic.DIVISION_BY_ZERO); } return result; } /** * @dev Variant of {tryModExp} that supports inputs of arbitrary length. */ function tryModExp( bytes memory b, bytes memory e, bytes memory m ) internal view returns (bool success, bytes memory result) { if (_zeroBytes(m)) return (false, new bytes(0)); uint256 mLen = m.length; // Encode call args in result and move the free memory pointer result = abi.encodePacked(b.length, e.length, mLen, b, e, m); assembly ("memory-safe") { let dataPtr := add(result, 0x20) // Write result on top of args to avoid allocating extra memory. success := staticcall(gas(), 0x05, dataPtr, mload(result), dataPtr, mLen) // Overwrite the length. // result.length > returndatasize() is guaranteed because returndatasize() == m.length mstore(result, mLen) // Set the memory pointer after the returned data. mstore(0x40, add(dataPtr, mLen)) } } /** * @dev Returns whether the provided byte array is zero. */ function _zeroBytes(bytes memory byteArray) private pure returns (bool) { for (uint256 i = 0; i < byteArray.length; ++i) { if (byteArray[i] != 0) { return false; } } return true; } /** * @dev Returns the square root of a number. If the number is not a perfect square, the value is rounded * towards zero. * * This method is based on Newton's method for computing square roots; the algorithm is restricted to only * using integer operations. */ function sqrt(uint256 a) internal pure returns (uint256) { unchecked { // Take care of easy edge cases when a == 0 or a == 1 if (a <= 1) { return a; } // In this function, we use Newton's method to get a root of `f(x) := x² - a`. It involves building a // sequence x_n that converges toward sqrt(a). For each iteration x_n, we also define the error between // the current value as `ε_n = | x_n - sqrt(a) |`. // // For our first estimation, we consider `e` the smallest power of 2 which is bigger than the square root // of the target. (i.e. `2**(e-1) ≤ sqrt(a) < 2**e`). We know that `e ≤ 128` because `(2¹²⁸)² = 2²⁵⁶` is // bigger than any uint256. // // By noticing that // `2**(e-1) ≤ sqrt(a) < 2**e → (2**(e-1))² ≤ a < (2**e)² → 2**(2*e-2) ≤ a < 2**(2*e)` // we can deduce that `e - 1` is `log2(a) / 2`. We can thus compute `x_n = 2**(e-1)` using a method similar // to the msb function. uint256 aa = a; uint256 xn = 1; if (aa >= (1 << 128)) { aa >>= 128; xn <<= 64; } if (aa >= (1 << 64)) { aa >>= 64; xn <<= 32; } if (aa >= (1 << 32)) { aa >>= 32; xn <<= 16; } if (aa >= (1 << 16)) { aa >>= 16; xn <<= 8; } if (aa >= (1 << 8)) { aa >>= 8; xn <<= 4; } if (aa >= (1 << 4)) { aa >>= 4; xn <<= 2; } if (aa >= (1 << 2)) { xn <<= 1; } // We now have x_n such that `x_n = 2**(e-1) ≤ sqrt(a) < 2**e = 2 * x_n`. This implies ε_n ≤ 2**(e-1). // // We can refine our estimation by noticing that the middle of that interval minimizes the error. // If we move x_n to equal 2**(e-1) + 2**(e-2), then we reduce the error to ε_n ≤ 2**(e-2). // This is going to be our x_0 (and ε_0) xn = (3 * xn) >> 1; // ε_0 := | x_0 - sqrt(a) | ≤ 2**(e-2) // From here, Newton's method give us: // x_{n+1} = (x_n + a / x_n) / 2 // // One should note that: // x_{n+1}² - a = ((x_n + a / x_n) / 2)² - a // = ((x_n² + a) / (2 * x_n))² - a // = (x_n⁴ + 2 * a * x_n² + a²) / (4 * x_n²) - a // = (x_n⁴ + 2 * a * x_n² + a² - 4 * a * x_n²) / (4 * x_n²) // = (x_n⁴ - 2 * a * x_n² + a²) / (4 * x_n²) // = (x_n² - a)² / (2 * x_n)² // = ((x_n² - a) / (2 * x_n))² // ≥ 0 // Which proves that for all n ≥ 1, sqrt(a) ≤ x_n // // This gives us the proof of quadratic convergence of the sequence: // ε_{n+1} = | x_{n+1} - sqrt(a) | // = | (x_n + a / x_n) / 2 - sqrt(a) | // = | (x_n² + a - 2*x_n*sqrt(a)) / (2 * x_n) | // = | (x_n - sqrt(a))² / (2 * x_n) | // = | ε_n² / (2 * x_n) | // = ε_n² / | (2 * x_n) | // // For the first iteration, we have a special case where x_0 is known: // ε_1 = ε_0² / | (2 * x_0) | // ≤ (2**(e-2))² / (2 * (2**(e-1) + 2**(e-2))) // ≤ 2**(2*e-4) / (3 * 2**(e-1)) // ≤ 2**(e-3) / 3 // ≤ 2**(e-3-log2(3)) // ≤ 2**(e-4.5) // // For the following iterations, we use the fact that, 2**(e-1) ≤ sqrt(a) ≤ x_n: // ε_{n+1} = ε_n² / | (2 * x_n) | // ≤ (2**(e-k))² / (2 * 2**(e-1)) // ≤ 2**(2*e-2*k) / 2**e // ≤ 2**(e-2*k) xn = (xn + a / xn) >> 1; // ε_1 := | x_1 - sqrt(a) | ≤ 2**(e-4.5) -- special case, see above xn = (xn + a / xn) >> 1; // ε_2 := | x_2 - sqrt(a) | ≤ 2**(e-9) -- general case with k = 4.5 xn = (xn + a / xn) >> 1; // ε_3 := | x_3 - sqrt(a) | ≤ 2**(e-18) -- general case with k = 9 xn = (xn + a / xn) >> 1; // ε_4 := | x_4 - sqrt(a) | ≤ 2**(e-36) -- general case with k = 18 xn = (xn + a / xn) >> 1; // ε_5 := | x_5 - sqrt(a) | ≤ 2**(e-72) -- general case with k = 36 xn = (xn + a / xn) >> 1; // ε_6 := | x_6 - sqrt(a) | ≤ 2**(e-144) -- general case with k = 72 // Because e ≤ 128 (as discussed during the first estimation phase), we know have reached a precision // ε_6 ≤ 2**(e-144) < 1. Given we're operating on integers, then we can ensure that xn is now either // sqrt(a) or sqrt(a) + 1. return xn - SafeCast.toUint(xn > a / xn); } } /** * @dev Calculates sqrt(a), following the selected rounding direction. */ function sqrt(uint256 a, Rounding rounding) internal pure returns (uint256) { unchecked { uint256 result = sqrt(a); return result + SafeCast.toUint(unsignedRoundsUp(rounding) && result * result < a); } } /** * @dev Return the log in base 2 of a positive value rounded towards zero. * Returns 0 if given 0. */ function log2(uint256 value) internal pure returns (uint256) { uint256 result = 0; uint256 exp; unchecked { exp = 128 * SafeCast.toUint(value > (1 << 128) - 1); value >>= exp; result += exp; exp = 64 * SafeCast.toUint(value > (1 << 64) - 1); value >>= exp; result += exp; exp = 32 * SafeCast.toUint(value > (1 << 32) - 1); value >>= exp; result += exp; exp = 16 * SafeCast.toUint(value > (1 << 16) - 1); value >>= exp; result += exp; exp = 8 * SafeCast.toUint(value > (1 << 8) - 1); value >>= exp; result += exp; exp = 4 * SafeCast.toUint(value > (1 << 4) - 1); value >>= exp; result += exp; exp = 2 * SafeCast.toUint(value > (1 << 2) - 1); value >>= exp; result += exp; result += SafeCast.toUint(value > 1); } return result; } /** * @dev Return the log in base 2, following the selected rounding direction, of a positive value. * Returns 0 if given 0. */ function log2(uint256 value, Rounding rounding) internal pure returns (uint256) { unchecked { uint256 result = log2(value); return result + SafeCast.toUint(unsignedRoundsUp(rounding) && 1 << result < value); } } /** * @dev Return the log in base 10 of a positive value rounded towards zero. * Returns 0 if given 0. */ function log10(uint256 value) internal pure returns (uint256) { uint256 result = 0; unchecked { if (value >= 10 ** 64) { value /= 10 ** 64; result += 64; } if (value >= 10 ** 32) { value /= 10 ** 32; result += 32; } if (value >= 10 ** 16) { value /= 10 ** 16; result += 16; } if (value >= 10 ** 8) { value /= 10 ** 8; result += 8; } if (value >= 10 ** 4) { value /= 10 ** 4; result += 4; } if (value >= 10 ** 2) { value /= 10 ** 2; result += 2; } if (value >= 10 ** 1) { result += 1; } } return result; } /** * @dev Return the log in base 10, following the selected rounding direction, of a positive value. * Returns 0 if given 0. */ function log10(uint256 value, Rounding rounding) internal pure returns (uint256) { unchecked { uint256 result = log10(value); return result + SafeCast.toUint(unsignedRoundsUp(rounding) && 10 ** result < value); } } /** * @dev Return the log in base 256 of a positive value rounded towards zero. * Returns 0 if given 0. * * Adding one to the result gives the number of pairs of hex symbols needed to represent `value` as a hex string. */ function log256(uint256 value) internal pure returns (uint256) { uint256 result = 0; uint256 isGt; unchecked { isGt = SafeCast.toUint(value > (1 << 128) - 1); value >>= isGt * 128; result += isGt * 16; isGt = SafeCast.toUint(value > (1 << 64) - 1); value >>= isGt * 64; result += isGt * 8; isGt = SafeCast.toUint(value > (1 << 32) - 1); value >>= isGt * 32; result += isGt * 4; isGt = SafeCast.toUint(value > (1 << 16) - 1); value >>= isGt * 16; result += isGt * 2; result += SafeCast.toUint(value > (1 << 8) - 1); } return result; } /** * @dev Return the log in base 256, following the selected rounding direction, of a positive value. * Returns 0 if given 0. */ function log256(uint256 value, Rounding rounding) internal pure returns (uint256) { unchecked { uint256 result = log256(value); return result + SafeCast.toUint(unsignedRoundsUp(rounding) && 1 << (result << 3) < value); } } /** * @dev Returns whether a provided rounding mode is considered rounding up for unsigned integers. */ function unsignedRoundsUp(Rounding rounding) internal pure returns (bool) { return uint8(rounding) % 2 == 1; } } // lib/openzeppelin-contracts/contracts/access/Ownable2Step.sol // OpenZeppelin Contracts (last updated v5.1.0) (access/Ownable2Step.sol) /** * @dev Contract module which provides access control mechanism, where * there is an account (an owner) that can be granted exclusive access to * specific functions. * * This extension of the {Ownable} contract includes a two-step mechanism to transfer * ownership, where the new owner must call {acceptOwnership} in order to replace the * old one. This can help prevent common mistakes, such as transfers of ownership to * incorrect accounts, or to contracts that are unable to interact with the * permission system. * * The initial owner is specified at deployment time in the constructor for `Ownable`. This * can later be changed with {transferOwnership} and {acceptOwnership}. * * This module is used through inheritance. It will make available all functions * from parent (Ownable). */ abstract contract Ownable2Step is Ownable { address private _pendingOwner; event OwnershipTransferStarted(address indexed previousOwner, address indexed newOwner); /** * @dev Returns the address of the pending owner. */ function pendingOwner() public view virtual returns (address) { return _pendingOwner; } /** * @dev Starts the ownership transfer of the contract to a new account. Replaces the pending transfer if there is one. * Can only be called by the current owner. * * Setting `newOwner` to the zero address is allowed; this can be used to cancel an initiated ownership transfer. */ function transferOwnership(address newOwner) public virtual override onlyOwner { _pendingOwner = newOwner; emit OwnershipTransferStarted(owner(), newOwner); } /** * @dev Transfers ownership of the contract to a new account (`newOwner`) and deletes any pending owner. * Internal function without access restriction. */ function _transferOwnership(address newOwner) internal virtual override { delete _pendingOwner; super._transferOwnership(newOwner); } /** * @dev The new owner accepts the ownership transfer. */ function acceptOwnership() public virtual { address sender = _msgSender(); if (pendingOwner() != sender) { revert OwnableUnauthorizedAccount(sender); } _transferOwnership(sender); } } // lib/openzeppelin-contracts/contracts/interfaces/IERC1363.sol // OpenZeppelin Contracts (last updated v5.1.0) (interfaces/IERC1363.sol) /** * @title IERC1363 * @dev Interface of the ERC-1363 standard as defined in the https://eips.ethereum.org/EIPS/eip-1363[ERC-1363]. * * Defines an extension interface for ERC-20 tokens that supports executing code on a recipient contract * after `transfer` or `transferFrom`, or code on a spender contract after `approve`, in a single transaction. */ interface IERC1363 is IERC20, IERC165 { /* * Note: the ERC-165 identifier for this interface is 0xb0202a11. * 0xb0202a11 === * bytes4(keccak256('transferAndCall(address,uint256)')) ^ * bytes4(keccak256('transferAndCall(address,uint256,bytes)')) ^ * bytes4(keccak256('transferFromAndCall(address,address,uint256)')) ^ * bytes4(keccak256('transferFromAndCall(address,address,uint256,bytes)')) ^ * bytes4(keccak256('approveAndCall(address,uint256)')) ^ * bytes4(keccak256('approveAndCall(address,uint256,bytes)')) */ /** * @dev Moves a `value` amount of tokens from the caller's account to `to` * and then calls {IERC1363Receiver-onTransferReceived} on `to`. * @param to The address which you want to transfer to. * @param value The amount of tokens to be transferred. * @return A boolean value indicating whether the operation succeeded unless throwing. */ function transferAndCall(address to, uint256 value) external returns (bool); /** * @dev Moves a `value` amount of tokens from the caller's account to `to` * and then calls {IERC1363Receiver-onTransferReceived} on `to`. * @param to The address which you want to transfer to. * @param value The amount of tokens to be transferred. * @param data Additional data with no specified format, sent in call to `to`. * @return A boolean value indicating whether the operation succeeded unless throwing. */ function transferAndCall(address to, uint256 value, bytes calldata data) external returns (bool); /** * @dev Moves a `value` amount of tokens from `from` to `to` using the allowance mechanism * and then calls {IERC1363Receiver-onTransferReceived} on `to`. * @param from The address which you want to send tokens from. * @param to The address which you want to transfer to. * @param value The amount of tokens to be transferred. * @return A boolean value indicating whether the operation succeeded unless throwing. */ function transferFromAndCall(address from, address to, uint256 value) external returns (bool); /** * @dev Moves a `value` amount of tokens from `from` to `to` using the allowance mechanism * and then calls {IERC1363Receiver-onTransferReceived} on `to`. * @param from The address which you want to send tokens from. * @param to The address which you want to transfer to. * @param value The amount of tokens to be transferred. * @param data Additional data with no specified format, sent in call to `to`. * @return A boolean value indicating whether the operation succeeded unless throwing. */ function transferFromAndCall(address from, address to, uint256 value, bytes calldata data) external returns (bool); /** * @dev Sets a `value` amount of tokens as the allowance of `spender` over the * caller's tokens and then calls {IERC1363Spender-onApprovalReceived} on `spender`. * @param spender The address which will spend the funds. * @param value The amount of tokens to be spent. * @return A boolean value indicating whether the operation succeeded unless throwing. */ function approveAndCall(address spender, uint256 value) external returns (bool); /** * @dev Sets a `value` amount of tokens as the allowance of `spender` over the * caller's tokens and then calls {IERC1363Spender-onApprovalReceived} on `spender`. * @param spender The address which will spend the funds. * @param value The amount of tokens to be spent. * @param data Additional data with no specified format, sent in call to `spender`. * @return A boolean value indicating whether the operation succeeded unless throwing. */ function approveAndCall(address spender, uint256 value, bytes calldata data) external returns (bool); } // lib/openzeppelin-contracts/contracts/token/ERC20/utils/SafeERC20.sol // OpenZeppelin Contracts (last updated v5.1.0) (token/ERC20/utils/SafeERC20.sol) /** * @title SafeERC20 * @dev Wrappers around ERC-20 operations that throw on failure (when the token * contract returns false). Tokens that return no value (and instead revert or * throw on failure) are also supported, non-reverting calls are assumed to be * successful. * To use this library you can add a `using SafeERC20 for IERC20;` statement to your contract, * which allows you to call the safe operations as `token.safeTransfer(...)`, etc. */ library SafeERC20 { /** * @dev An operation with an ERC-20 token failed. */ error SafeERC20FailedOperation(address token); /** * @dev Indicates a failed `decreaseAllowance` request. */ error SafeERC20FailedDecreaseAllowance(address spender, uint256 currentAllowance, uint256 requestedDecrease); /** * @dev Transfer `value` amount of `token` from the calling contract to `to`. If `token` returns no value, * non-reverting calls are assumed to be successful. */ function safeTransfer(IERC20 token, address to, uint256 value) internal { _callOptionalReturn(token, abi.encodeCall(token.transfer, (to, value))); } /** * @dev Transfer `value` amount of `token` from `from` to `to`, spending the approval given by `from` to the * calling contract. If `token` returns no value, non-reverting calls are assumed to be successful. */ function safeTransferFrom(IERC20 token, address from, address to, uint256 value) internal { _callOptionalReturn(token, abi.encodeCall(token.transferFrom, (from, to, value))); } /** * @dev Increase the calling contract's allowance toward `spender` by `value`. If `token` returns no value, * non-reverting calls are assumed to be successful. * * IMPORTANT: If the token implements ERC-7674 (ERC-20 with temporary allowance), and if the "client" * smart contract uses ERC-7674 to set temporary allowances, then the "client" smart contract should avoid using * this function. Performing a {safeIncreaseAllowance} or {safeDecreaseAllowance} operation on a token contract * that has a non-zero temporary allowance (for that particular owner-spender) will result in unexpected behavior. */ function safeIncreaseAllowance(IERC20 token, address spender, uint256 value) internal { uint256 oldAllowance = token.allowance(address(this), spender); forceApprove(token, spender, oldAllowance + value); } /** * @dev Decrease the calling contract's allowance toward `spender` by `requestedDecrease`. If `token` returns no * value, non-reverting calls are assumed to be successful. * * IMPORTANT: If the token implements ERC-7674 (ERC-20 with temporary allowance), and if the "client" * smart contract uses ERC-7674 to set temporary allowances, then the "client" smart contract should avoid using * this function. Performing a {safeIncreaseAllowance} or {safeDecreaseAllowance} operation on a token contract * that has a non-zero temporary allowance (for that particular owner-spender) will result in unexpected behavior. */ function safeDecreaseAllowance(IERC20 token, address spender, uint256 requestedDecrease) internal { unchecked { uint256 currentAllowance = token.allowance(address(this), spender); if (currentAllowance < requestedDecrease) { revert SafeERC20FailedDecreaseAllowance(spender, currentAllowance, requestedDecrease); } forceApprove(token, spender, currentAllowance - requestedDecrease); } } /** * @dev Set the calling contract's allowance toward `spender` to `value`. If `token` returns no value, * non-reverting calls are assumed to be successful. Meant to be used with tokens that require the approval * to be set to zero before setting it to a non-zero value, such as USDT. * * NOTE: If the token implements ERC-7674, this function will not modify any temporary allowance. This function * only sets the "standard" allowance. Any temporary allowance will remain active, in addition to the value being * set here. */ function forceApprove(IERC20 token, address spender, uint256 value) internal { bytes memory approvalCall = abi.encodeCall(token.approve, (spender, value)); if (!_callOptionalReturnBool(token, approvalCall)) { _callOptionalReturn(token, abi.encodeCall(token.approve, (spender, 0))); _callOptionalReturn(token, approvalCall); } } /** * @dev Performs an {ERC1363} transferAndCall, with a fallback to the simple {ERC20} transfer if the target has no * code. This can be used to implement an {ERC721}-like safe transfer that rely on {ERC1363} checks when * targeting contracts. * * Reverts if the returned value is other than `true`. */ function transferAndCallRelaxed(IERC1363 token, address to, uint256 value, bytes memory data) internal { if (to.code.length == 0) { safeTransfer(token, to, value); } else if (!token.transferAndCall(to, value, data)) { revert SafeERC20FailedOperation(address(token)); } } /** * @dev Performs an {ERC1363} transferFromAndCall, with a fallback to the simple {ERC20} transferFrom if the target * has no code. This can be used to implement an {ERC721}-like safe transfer that rely on {ERC1363} checks when * targeting contracts. * * Reverts if the returned value is other than `true`. */ function transferFromAndCallRelaxed( IERC1363 token, address from, address to, uint256 value, bytes memory data ) internal { if (to.code.length == 0) { safeTransferFrom(token, from, to, value); } else if (!token.transferFromAndCall(from, to, value, data)) { revert SafeERC20FailedOperation(address(token)); } } /** * @dev Performs an {ERC1363} approveAndCall, with a fallback to the simple {ERC20} approve if the target has no * code. This can be used to implement an {ERC721}-like safe transfer that rely on {ERC1363} checks when * targeting contracts. * * NOTE: When the recipient address (`to`) has no code (i.e. is an EOA), this function behaves as {forceApprove}. * Opposedly, when the recipient address (`to`) has code, this function only attempts to call {ERC1363-approveAndCall} * once without retrying, and relies on the returned value to be true. * * Reverts if the returned value is other than `true`. */ function approveAndCallRelaxed(IERC1363 token, address to, uint256 value, bytes memory data) internal { if (to.code.length == 0) { forceApprove(token, to, value); } else if (!token.approveAndCall(to, value, data)) { revert SafeERC20FailedOperation(address(token)); } } /** * @dev Imitates a Solidity high-level call (i.e. a regular function call to a contract), relaxing the requirement * on the return value: the return value is optional (but if data is returned, it must not be false). * @param token The token targeted by the call. * @param data The call data (encoded using abi.encode or one of its variants). * * This is a variant of {_callOptionalReturnBool} that reverts if call fails to meet the requirements. */ function _callOptionalReturn(IERC20 token, bytes memory data) private { uint256 returnSize; uint256 returnValue; assembly ("memory-safe") { let success := call(gas(), token, 0, add(data, 0x20), mload(data), 0, 0x20) // bubble errors if iszero(success) { let ptr := mload(0x40) returndatacopy(ptr, 0, returndatasize()) revert(ptr, returndatasize()) } returnSize := returndatasize() returnValue := mload(0) } if (returnSize == 0 ? address(token).code.length == 0 : returnValue != 1) { revert SafeERC20FailedOperation(address(token)); } } /** * @dev Imitates a Solidity high-level call (i.e. a regular function call to a contract), relaxing the requirement * on the return value: the return value is optional (but if data is returned, it must not be false). * @param token The token targeted by the call. * @param data The call data (encoded using abi.encode or one of its variants). * * This is a variant of {_callOptionalReturn} that silently catches all reverts and returns a bool instead. */ function _callOptionalReturnBool(IERC20 token, bytes memory data) private returns (bool) { bool success; uint256 returnSize; uint256 returnValue; assembly ("memory-safe") { success := call(gas(), token, 0, add(data, 0x20), mload(data), 0, 0x20) returnSize := returndatasize() returnValue := mload(0) } return success && (returnSize == 0 ? address(token).code.length > 0 : returnValue == 1); } } // src/base/ConversionRoutes.sol /// @title ConversionRoutes /// @notice Shared machinery for turning an arbitrary asset into the quote token, with the /// minimum output bounded by that asset's own Chainlink mark. /// /// @dev Both {Pot} and {POLTreasury} need this and there is exactly ONE implementation of /// it on purpose. A Chainlink-bounded swap is the most security-sensitive code in the /// repo; having two copies would double the surface an auditor has to check and /// guarantee they drift. Everything here is configuration — route, fee tier, slippage /// bound, per-call cap, staleness limit — so adding an asset is a multisig call. /// /// THREE PROPERTIES EVERY CONVERSION HAS: /// 1. Bounded by Chainlink. `amountOutMinimum` comes from the feed, never from a quote. /// 2. Capped per call, so a large balance cannot be walked through the pool in one /// swap. Verified on a Base fork: an uncapped 500 ETH breached its bound and was /// refused, while capped conversions landed comfortably inside it. /// 3. Measured by balance delta, never by the router's return value, so a token that /// lies about transferring cannot inflate what we think we received. /// @dev UNISWAP V3 CALLDATA, AND ONLY UNISWAP V3 CALLDATA. /// /// This contract encodes exactly one swap shape: `IUniswapV3SwapRouter`'s 7-field /// `exactInputSingle`. It does NOT encode Aerodrome Slipstream's 8-field variant /// (tickSpacing + deadline), and it never has — there is no dead branch here, and /// `ISlipstreamSwapRouter` is not imported. /// /// **That is a design decision, not an omission.** ASSUMPTIONS A-16 established that the /// liquidity Chipworks converts against is on Uniswap v3, not Slipstream. Both live /// routes — WETH and AERO — trade in Uniswap v3 pools. Aerodrome appears in this /// protocol only in `POLTreasury`, and only for LP positions and gauge staking through /// the Slipstream position manager, never for a swap. `ChipRounds` does encode the /// Slipstream shape, because stock BUYS may route through either venue; that is a /// different contract with a different job. /// /// External review (TRIAGE SEC-POT-001) noted that pointing a route at a Slipstream /// router would revert on the ABI mismatch. Correct — so {_setRoute} now refuses any /// router whose `factory()` is not the Uniswap v3 factory, which a Slipstream router's /// never is. The misconfiguration is rejected at configuration time rather than /// discovered at conversion time. abstract contract ConversionRoutes { using SafeERC20 for IERC20; uint256 public constant BPS = 10_000; /// @notice Gas cap on the one-off `decimals()` probe when registering a route. uint256 public constant PROBE_GAS = 50_000; /// @notice Asset every route converts into. address public immutable quoteToken; /// @notice Cached decimals of `quoteToken`. uint8 public immutable quoteDecimals; /// @notice Wrapped native token. Native ETH is wrapped into this on the way through. address public weth; /// @notice The Uniswap v3 factory every routed router must belong to. /// @dev Immutable and constructor-set rather than a wiring call, deliberately: an /// optional guard that silently does nothing when forgotten is the anti-pattern this /// repo already documents once (the `setCustodian` trap in LAUNCH_CONFIG). This one /// cannot be forgotten. address public immutable uniswapV3Factory; /// @notice Chainlink L2 sequencer uptime feed. Zero disables the check. address public sequencerUptimeFeed; /// @notice How long after the sequencer comes back before prices are trusted again. uint64 public sequencerGracePeriod; struct Route { bool enabled; address feed; // Chainlink /USD aggregator address router; // Uniswap v3 style router uint24 fee; // pool fee tier uint32 maxSlippageBps; // how far below the Chainlink mark execution may land uint128 maxPerCall; // largest amount one convert() may push through the pool uint128 minPerCall; // smallest amount worth converting. 0 disables the floor uint64 maxFeedAge; // reject a feed older than this. 0 disables the check uint8 tokenDecimals; // cached uint8 feedDecimals; // cached } mapping(address token => Route) internal _routes; address[] internal _routedTokens; event Converted(address indexed token, uint256 amountIn, uint256 quoteOut, uint256 minOut, address indexed caller); event RouteSet( address indexed token, address feed, address router, uint24 fee, uint32 slippageBps, uint128 cap, uint64 maxFeedAge ); event RouteDisabled(address indexed token); event SequencerFeedUpdated(address indexed feed, uint64 gracePeriod); event WethUpdated(address indexed previousWeth, address indexed newWeth); error RouteZeroAddress(); error RouteBadConfig(); error StaleFeed(uint256 updatedAt, uint256 maxAge); error BadFeedAnswer(); error UnderMinOut(uint256 received, uint256 minOut); error NoRoute(address token); error CannotRouteQuoteToken(); error NothingToConvert(); /// @dev Raised when the amount is so small that the Chainlink-derived minimum output /// rounds to zero. Swapping then would be an unbounded swap, so it is refused. /// Dust simply waits until enough accumulates to be priced. error AmountTooSmall(uint256 amountIn); /// @notice The router is not a Uniswap v3 router of the expected factory. SEC-POT-001. error RouterNotUniswapV3(address router); /// @notice The feed is pinned at its aggregator's floor or ceiling, so the price is a /// circuit-breaker artefact rather than a market price. SEC-POT-005. error FeedAtBand(int256 answer); /// @notice The L2 sequencer is down, or has not been back long enough to trust. SEC-POT-003. error SequencerDown(); error SequencerGracePeriod(uint256 backAt, uint64 graceEndsAt); /// @notice Below the route's `minPerCall` floor. SEC-POT-004. error BelowMinPerCall(uint256 amountIn, uint128 minPerCall); /// @notice A caller-supplied `minOut` the Chainlink floor could not be raised to meet. error NotAContract(address target); constructor(address quoteToken_, address uniswapV3Factory_) { if (quoteToken_ == address(0) || uniswapV3Factory_ == address(0)) revert RouteZeroAddress(); quoteToken = quoteToken_; quoteDecimals = IDecimals(quoteToken_).decimals(); uniswapV3Factory = uniswapV3Factory_; } /* ------------------------------------------------------------------ */ /* VIEWS */ /* ------------------------------------------------------------------ */ function routeOf(address token) external view returns (Route memory) { return _routes[token]; } function routedTokens() external view returns (address[] memory) { return _routedTokens; } /// @notice ETH plus WETH waiting to be converted, before the per-call cap. function convertibleBalance() public view returns (uint256) { uint256 wethBalance = weth == address(0) ? 0 : IERC20(weth).balanceOf(address(this)); return address(this).balance + wethBalance; } /// @notice Balance of `token` waiting to be converted, before the per-call cap. /// @dev For WETH this includes native ETH, since ETH is wrapped on the way through. function convertibleBalance(address token) public view returns (uint256) { if (token == weth) return convertibleBalance(); return IERC20(token).balanceOf(address(this)); } /// @notice How much the next conversion of `token` would push through the pool. function nextConversionAmount(address token) public view returns (uint256) { uint256 total = convertibleBalance(token); uint256 cap = _routes[token].maxPerCall; return (cap != 0 && total > cap) ? cap : total; } /// @notice Minimum quote-token output a conversion of `amount` would insist on. function minOutFor(address token, uint256 amount) public view returns (uint256) { Route storage r = _routes[token]; if (!r.enabled) revert NoRoute(token); uint256 answer = _readFeed(r.feed, r.maxFeedAge); // amount (tokenDecimals) x USD per token -> quote units, then the slippage haircut. uint256 gross = (amount * answer * (10 ** quoteDecimals)) / (10 ** r.feedDecimals) / (10 ** r.tokenDecimals); return (gross * (BPS - r.maxSlippageBps)) / BPS; } /* ------------------------------------------------------------------ */ /* INTERNALS */ /* ------------------------------------------------------------------ */ /// @notice Read a Chainlink answer with every check this contract insists on: the /// sequencer is up and has been for the grace period, the answer is positive, /// it is not older than `maxAge`, and it is not pinned at the aggregator's /// circuit-breaker band. /// @dev ONE implementation, for the same reason there is one `_convert`. {POLTreasury} /// prices its POL assets through this to bound LP execution (H-02), and `minOutFor` /// prices swaps through it. If a future change makes a feed check stricter, both /// inherit it; there is no second copy to forget. /// @return answer The raw feed answer. Its decimals are the caller's cached `feedDecimals`. function _readFeed(address feed, uint64 maxAge) internal view returns (uint256 answer) { _requireSequencerUp(); (, int256 raw,, uint256 updatedAt,) = IAggregatorV3(feed).latestRoundData(); if (raw <= 0) revert BadFeedAnswer(); if (maxAge != 0 && block.timestamp > updatedAt + maxAge) revert StaleFeed(updatedAt, maxAge); _requireInBand(feed, raw); return uint256(raw); } /// @param callerMinOut A floor the caller insists on, on top of the Chainlink one. Zero /// means "no opinion". SEC-POT-002: `convert` is permissionless so anyone can push /// it along, but that also means it executes against whatever the pool says at the /// moment it lands, bounded only by a 2% Chainlink haircut. A keeper holding a real /// quote can pass a tighter number and refuse a worse fill. The floor can only ever /// be raised — a caller cannot widen the Chainlink bound, only tighten it. function _convert(address token, uint256 callerMinOut) internal returns (uint256 amountIn, uint256 quoteOut) { Route storage r = _routes[token]; amountIn = nextConversionAmount(token); if (amountIn == 0) revert NothingToConvert(); // SEC-POT-004: a dust-sized conversion pays a full swap's gas and moves the pool for // nothing. Below the floor it simply waits for more to accumulate. if (r.minPerCall != 0 && amountIn < r.minPerCall) revert BelowMinPerCall(amountIn, r.minPerCall); uint256 minOut = minOutFor(token, amountIn); if (minOut == 0) revert AmountTooSmall(amountIn); if (callerMinOut > minOut) minOut = callerMinOut; // Wrap only the shortfall: WETH already held is used as-is. if (token == weth) { uint256 wethBalance = IERC20(weth).balanceOf(address(this)); if (wethBalance < amountIn) IWETH(weth).deposit{value: amountIn - wethBalance}(); } uint256 before = IERC20(quoteToken).balanceOf(address(this)); IERC20(token).forceApprove(r.router, amountIn); IUniswapV3SwapRouter(r.router) .exactInputSingle( IUniswapV3SwapRouter.ExactInputSingleParams({ tokenIn: token, tokenOut: quoteToken, fee: r.fee, recipient: address(this), amountIn: amountIn, amountOutMinimum: minOut, sqrtPriceLimitX96: 0 }) ); IERC20(token).forceApprove(r.router, 0); // Trust the measured delta, never the router's return value. quoteOut = IERC20(quoteToken).balanceOf(address(this)) - before; if (quoteOut < minOut) revert UnderMinOut(quoteOut, minOut); emit Converted(token, amountIn, quoteOut, minOut, msg.sender); } /// @dev SEC-POT-003. On an L2 a Chainlink feed keeps returning its last answer while the /// sequencer is down, so "fresh enough" is not the same as "true". Chipworks /// converts against that price, so a stale-but-recent mark is exactly the input an /// arbitrageur wants us to trade on when the chain comes back. /// /// Standard Base hygiene: `answer == 0` means up, anything else means down, and a /// grace period after it returns stops us trading on the first, thinnest blocks. /// Zero feed disables the check, so this is inert until configured and every /// existing test is unaffected. function _requireSequencerUp() internal view { address feed = sequencerUptimeFeed; if (feed == address(0)) return; (, int256 up, uint256 startedAt,,) = IAggregatorV3(feed).latestRoundData(); if (up != 0) revert SequencerDown(); uint64 grace = sequencerGracePeriod; if (grace != 0 && block.timestamp < startedAt + grace) { revert SequencerGracePeriod(startedAt, uint64(startedAt) + grace); } } /// @dev SEC-POT-005. A Chainlink aggregator clamps its answer to `minAnswer`/`maxAnswer`. /// In a crash the feed reports the FLOOR, not the market — which here would inflate /// the expected output and make every conversion of that token revert `UnderMinOut` /// for as long as the price stayed pinned. Reverting is the safe direction, but /// reverting with a misleading reason is not: this fails as {FeedAtBand} so an /// operator can tell "the pool moved" from "the oracle is at its circuit breaker". /// /// The band lives on the AGGREGATOR behind the proxy, and not every feed exposes it. /// Both hops are gas-capped staticcalls and a feed that does not answer simply skips /// the check — this must never be the reason a healthy conversion fails. /// /// Recovery if a token does get pinned: `disableRoute(token)` then /// `sweepNonQuote(token, ...)`. Both already existed; see TRIAGE SEC-POT-005. function _requireInBand(address feed, int256 answer) internal view { (bool okAgg, bytes memory aggRet) = feed.staticcall{gas: PROBE_GAS}(abi.encodeWithSignature("aggregator()")); if (!okAgg || aggRet.length < 32) return; address agg = abi.decode(aggRet, (address)); if (agg == address(0)) return; (bool okMin, bytes memory minRet) = agg.staticcall{gas: PROBE_GAS}(abi.encodeWithSignature("minAnswer()")); if (okMin && minRet.length >= 32) { int256 minAnswer = abi.decode(minRet, (int256)); if (answer <= minAnswer) revert FeedAtBand(answer); } (bool okMax, bytes memory maxRet) = agg.staticcall{gas: PROBE_GAS}(abi.encodeWithSignature("maxAnswer()")); if (okMax && maxRet.length >= 32) { int256 maxAnswer = abi.decode(maxRet, (int256)); if (answer >= maxAnswer) revert FeedAtBand(answer); } } function _setSequencerFeed(address feed, uint64 gracePeriod) internal { sequencerUptimeFeed = feed; sequencerGracePeriod = gracePeriod; emit SequencerFeedUpdated(feed, gracePeriod); } function _setWeth(address weth_) internal { if (weth_ == address(0)) revert RouteZeroAddress(); emit WethUpdated(weth, weth_); weth = weth_; } function _setRoute( address token, address feed, address router, uint24 fee, uint32 maxSlippageBps, uint128 maxPerCall, uint128 minPerCall, uint64 maxFeedAge ) internal { if (token == address(0) || feed == address(0) || router == address(0)) { revert RouteZeroAddress(); } if (token == quoteToken) revert CannotRouteQuoteToken(); if (fee == 0 || maxSlippageBps >= BPS || maxPerCall == 0) revert RouteBadConfig(); if (minPerCall > maxPerCall) revert RouteBadConfig(); // SEC-POT-001. This contract can only encode Uniswap v3 calldata, so it accepts only // a Uniswap v3 router. A Slipstream router reports the Slipstream factory and is // rejected here rather than reverting on an ABI mismatch at conversion time. _requireUniswapV3Router(router); uint8 tokenDecimals = _probeDecimals(token); uint8 feedDecimals = IAggregatorV3(feed).decimals(); if (feedDecimals == 0 || feedDecimals > 18) revert RouteBadConfig(); if (_routes[token].feed == address(0)) _routedTokens.push(token); _routes[token] = Route({ enabled: true, feed: feed, router: router, fee: fee, maxSlippageBps: maxSlippageBps, maxPerCall: maxPerCall, minPerCall: minPerCall, maxFeedAge: maxFeedAge, tokenDecimals: tokenDecimals, feedDecimals: feedDecimals }); emit RouteSet(token, feed, router, fee, maxSlippageBps, maxPerCall, maxFeedAge); } function _disableRoute(address token) internal { _routes[token].enabled = false; emit RouteDisabled(token); } /// @dev Rejects anything that is not a Uniswap v3 router of our factory. The factory is /// the discriminator that actually holds: Aerodrome Slipstream is a separate /// protocol with a separate factory, so its router can never report ours. Not /// gas-capped and not tolerant of failure — this is configuration time, and a router /// that cannot answer `factory()` is one we should not be pointing money at. function _requireUniswapV3Router(address router) internal view { if (router.code.length == 0) revert NotAContract(router); (bool ok, bytes memory ret) = router.staticcall(abi.encodeWithSignature("factory()")); if (!ok || ret.length < 32) revert RouterNotUniswapV3(router); if (abi.decode(ret, (address)) != uniswapV3Factory) revert RouterNotUniswapV3(router); } /// @dev Gas-capped, per ASSUMPTIONS.md A-17. A token whose decimals cannot be read is /// rejected rather than guessed at: getting this wrong silently mis-prices every /// conversion of that token. function _probeDecimals(address token) internal view returns (uint8) { (bool ok, bytes memory ret) = token.staticcall{gas: PROBE_GAS}(abi.encodeWithSignature("decimals()")); if (!ok || ret.length != 32) revert RouteBadConfig(); uint256 d = abi.decode(ret, (uint256)); if (d == 0 || d > 36) revert RouteBadConfig(); return uint8(d); } } interface IDecimals { function decimals() external view returns (uint8); } // src/POLTreasury.sol /// @title POLTreasury /// @notice Protocol-owned liquidity. Receives the per-round stock holdback plus USDC, /// pairs them into Aerodrome Slipstream positions, and routes the income those /// positions throw off back to the FeeSplitter, where it re-enters the Pot. /// /// @dev THE MANAGER IS A HOT KEY, AND THIS CONTRACT IS WRITTEN AS IF IT IS ALREADY LEAKED. /// /// `manager` exists so the Bankr optimizer can move ranges without holding the keys to /// configuration. That is a session key on a server, so the only useful security claim /// is one that survives its loss. External review (TRIAGE batch 6, H-01/H-02) showed the /// earlier version did not: the per-operation allowance work was real but it hardened /// the wrong layer. Allowances were never the vector. **The vector was the parameters.** /// A leaked key could stake a position into a contract of its own choosing, or mint the /// whole USDC balance against a token it had just printed, with correctly-scoped, /// promptly-cleared approvals throughout. /// /// So every `onlyManager` entry point is now written to be safe for ANY arguments: /// /// 1. TOKENS ARE ALLOWLISTED. A position is always the quote token paired with a /// registered POL asset. There is no path that touches an arbitrary token. /// 2. POOLS ARE DERIVED, NOT SUPPLIED. The pool comes from the Slipstream factory for /// that exact pair and tick spacing, and `sqrtPriceX96` is forced to zero, so a /// caller can neither name a pool nor create one at a price of their choosing. /// 3. GAUGES ARE VERIFIED AGAINST THE VOTER. `voter.gauges(pool)` is the only thing /// that makes an address a gauge, with the pool derived from the position itself. /// 4. EXECUTION IS BOUNDED BY CHAINLINK. The pool's own price must sit inside a band /// around the POL asset's feed before liquidity moves in either direction. That /// band, not the caller's minimums, is what bounds the value that moves; blank /// minimums are refused on top of it as operator hygiene. /// /// What a leaked manager key can still do is move liquidity between honest ranges of /// honest pools at honest prices. It cannot send value anywhere, because no manager /// function has a destination argument at all. That is the claim, and it is enforced /// here rather than by key hygiene. /// /// @dev THE RESCUE RULE IS DIFFERENT HERE, ON PURPOSE. /// In ChipRewards, `recoverExcess` protects a computed sum of user credits, because /// that contract holds tokens on behalf of named claimants. POLTreasury does not: it /// holds protocol assets, so "balance minus owed" would protect nothing and the rescue /// would be an unrestricted drain. /// Instead the rescue works by strict exclusion. It can NEVER move: /// - the quote token, /// - any registered POL asset, /// - any registered income token, /// - the position manager itself, and so no position NFT. /// It can only move tokens the treasury does not recognise — stray airdrops. Anything /// the protocol actually owns leaves only through `forwardIncome` (to the splitter) or /// a manager action on a position. There is no path that sends POL assets to a wallet. /// /// ROLES. The multisig owns configuration. A separate `manager` role exists for the /// Bankr optimizer to move ranges and stake gauges without holding the keys to the /// configuration. Fee collection and income forwarding are permissionless, so income /// can always be pushed back to holders even if the optimizer goes quiet. contract POLTreasury is Ownable2Step, ReentrancyGuard, IERC721Receiver, ConversionRoutes { using SafeERC20 for IERC20; /// @notice Widest band a POL asset may be registered with: 10%. uint32 public constant MAX_DEVIATION_BPS = 1_000; /// @notice Aerodrome Slipstream position manager. INonfungiblePositionManager public immutable positionManager; /// @notice The concentrated-liquidity factory the position manager itself reports. /// @dev Read from `positionManager.factory()` at construction rather than passed in, so /// the pool check can never be pointed at a factory that disagrees with the manager /// the positions actually live in. address public immutable positionFactory; /// @notice Aerodrome's Voter. The only authority on which gauge belongs to which pool. IAerodromeVoter public immutable voter; /// @notice Where POL income is sent. The FeeSplitter, which then feeds the Pot. address public feeSplitter; /// @notice The Bankr optimizer. May manage positions, may not change configuration. address public manager; /// @notice ChipRewards, the only contract allowed to record compound credits. address public rewards; /// @notice A token this treasury deliberately holds as POL, and the feed that prices it. /// @dev The feed is MANDATORY. An optional price check that silently does nothing when /// the feed was forgotten is exactly the shape of guard this repo has already been /// bitten by once (the `setCustodian` trap in LAUNCH_CONFIG). A POL asset without a /// price is one no LP operation could bound, so it cannot be registered at all. struct PolAsset { bool registered; address feed; // Chainlink /USD uint8 tokenDecimals; // cached uint8 feedDecimals; // cached uint32 maxDeviationBps; // how far the pool price may sit from the feed uint64 maxFeedAge; // reject a feed older than this. 0 disables the check } mapping(address token => PolAsset) internal _polAssets; /// @notice Tokens that count as income and get forwarded to the splitter (AERO, /// collected fees). Never rescuable. mapping(address token => bool) public isIncomeToken; /// @notice Position NFTs this treasury holds. uint256[] public positionIds; mapping(uint256 tokenId => bool) public holdsPosition; /// @notice Which gauge a position is staked in, if any. Set only by `stakePosition`. mapping(uint256 tokenId => address) public stakedIn; /// @notice Compound-share ledger. USD value each holder has routed into POL. mapping(address owner => uint256) public compoundShares; uint256 public totalCompoundShares; event ManagerUpdated(address indexed previousManager, address indexed newManager); event FeeSplitterUpdated(address indexed previousSplitter, address indexed newSplitter); event RewardsUpdated(address indexed previousRewards, address indexed newRewards); event PolAssetSet(address indexed token, address feed, uint32 maxDeviationBps, uint64 maxFeedAge); event PolAssetRemoved(address indexed token); event IncomeTokenSet(address indexed token, bool isIncome); event PositionMinted(uint256 indexed tokenId, uint128 liquidity, uint256 amount0, uint256 amount1); event PositionRegistered(uint256 indexed tokenId); event PositionPruned(uint256 indexed tokenId); event LiquidityIncreased(uint256 indexed tokenId, uint128 liquidity, uint256 amount0, uint256 amount1); event LiquidityDecreased(uint256 indexed tokenId, uint256 amount0, uint256 amount1); event FeesCollected(uint256 indexed tokenId, uint256 amount0, uint256 amount1); event IncomeForwarded(address indexed token, uint256 amount, address indexed to); event CompoundRecorded(address indexed owner, address indexed token, uint256 amount, uint256 usdValue); event PositionStaked(uint256 indexed tokenId, address indexed gauge); event PositionUnstaked(uint256 indexed tokenId, address indexed gauge); event ExcessRecovered(address indexed token, address indexed to, uint256 amount); error ZeroAddress(); error NotManager(address caller); error NotRewards(address caller); error ProtectedToken(address token); error NothingToForward(address token); error UnknownPosition(uint256 tokenId); error NothingToRecover(address token); error BadConfig(); /// @notice H-01. The address is not the gauge Aerodrome's voter names for this pool. error GaugeNotCanonical(address gauge); /// @notice H-01. The gauge did not take custody, so a live approval would have been left. error GaugeDidNotCustody(address gauge); /// @notice H-02(a). A token in the pair is not a registered POL asset. error TokenNotPolAsset(address token); /// @notice H-02(a). Every POL position is quote-paired; neither side was the quote token. error NotQuotePaired(); /// @notice H-02(b). The Slipstream factory has no pool for that pair and tick spacing. error PoolNotCanonical(address pool); /// @notice H-02(c). The pool's price is outside the band around the POL asset's feed. error PoolPriceOffMark(uint256 poolPrice, uint256 markPrice); /// @notice H-02(c). The pool would not report a price at all. error PoolPriceUnavailable(address pool); /// @notice H-02(c)/(d). Minimums were blank or looser than the configured bound. error SlippageUnbounded(); /// @notice M-02. Income tokens must be disjoint from the quote token and POL assets. error TokenNotDisjoint(address token); /// @notice M-03. The position is still held here, or still staked, so it cannot be pruned. error PositionStillHeld(uint256 tokenId); constructor( address multisig, address quoteToken_, address positionManager_, address feeSplitter_, address uniswapV3Factory_, address voter_ ) Ownable(multisig) ConversionRoutes(quoteToken_, uniswapV3Factory_) { if ( multisig == address(0) || quoteToken_ == address(0) || positionManager_ == address(0) || feeSplitter_ == address(0) || voter_ == address(0) ) revert ZeroAddress(); positionManager = INonfungiblePositionManager(positionManager_); voter = IAerodromeVoter(voter_); address f = INonfungiblePositionManager(positionManager_).factory(); if (f == address(0)) revert ZeroAddress(); positionFactory = f; feeSplitter = feeSplitter_; emit FeeSplitterUpdated(address(0), feeSplitter_); } receive() external payable {} modifier onlyManager() { if (msg.sender != manager && msg.sender != owner()) revert NotManager(msg.sender); _; } /* ------------------------------------------------------------------ */ /* GOVERNANCE */ /* ------------------------------------------------------------------ */ function setManager(address newManager) external onlyOwner { emit ManagerUpdated(manager, newManager); manager = newManager; } function setFeeSplitter(address newSplitter) external onlyOwner { if (newSplitter == address(0)) revert ZeroAddress(); emit FeeSplitterUpdated(feeSplitter, newSplitter); feeSplitter = newSplitter; } function setRewards(address newRewards) external onlyOwner { emit RewardsUpdated(rewards, newRewards); rewards = newRewards; } /// @notice Register a token as POL, with the feed that bounds every LP operation on it. /// @dev Registration is what makes an asset usable in `mintPosition` at all, so this is /// the whole of the H-02(a) allowlist. Re-registering an existing asset updates its /// feed and band. function setPolAsset(address token, address feed, uint32 maxDeviationBps, uint64 maxFeedAge) external onlyOwner { if (token == address(0) || feed == address(0)) revert ZeroAddress(); if (token == quoteToken) revert TokenNotDisjoint(token); if (isIncomeToken[token]) revert TokenNotDisjoint(token); // M-02 if (maxDeviationBps == 0 || maxDeviationBps > MAX_DEVIATION_BPS) revert BadConfig(); uint8 feedDecimals = IAggregatorV3(feed).decimals(); if (feedDecimals == 0 || feedDecimals > 18) revert BadConfig(); _polAssets[token] = PolAsset({ registered: true, feed: feed, tokenDecimals: _probeDecimals(token), feedDecimals: feedDecimals, maxDeviationBps: maxDeviationBps, maxFeedAge: maxFeedAge }); emit PolAssetSet(token, feed, maxDeviationBps, maxFeedAge); } /// @notice Stop treating a token as POL. It stays protected from the rescue only while /// registered, so this is a deliberate two-consequence action. /// @dev There is no on-chain enumeration of POL assets: nothing in this contract iterates /// them, and the array plus its removal loop cost more code size than the repo's /// 24,000-byte budget had to spare. `PolAssetSet` and `PolAssetRemoved` carry the /// full history, so the set is reconstructible from logs. function removePolAsset(address token) external onlyOwner { if (!_polAssets[token].registered) revert TokenNotPolAsset(token); delete _polAssets[token]; emit PolAssetRemoved(token); } /// @notice Mark a token as income, so `forwardIncome` will push it to the splitter. /// @dev M-02. `forwardIncome` sends the FULL balance of an income token to the splitter, /// so an income token that was also a POL asset or the quote token would turn a /// permissionless function into a drain of pairing inventory. The two sets are kept /// disjoint here, in both directions — see also `setPolAsset`. function setIncomeToken(address token, bool isIncome) external onlyOwner { if (token == address(0)) revert ZeroAddress(); if (isIncome) { if (token == quoteToken || _polAssets[token].registered) revert TokenNotDisjoint(token); } isIncomeToken[token] = isIncome; emit IncomeTokenSet(token, isIncome); } /* ------------------------------------------------------------------ */ /* CONVERSION */ /* ------------------------------------------------------------------ */ /// @notice Turn an asset the treasury holds into the quote token, so it can be paired /// with the stock holdback. Permissionless. /// @dev POL receives its share of fees in whatever asset was flowing — ETH from the LP /// locker, AERO from gauges. Without this the slice arrives in a form POL cannot /// pair, which is the same gap the Pot had. Same Chainlink-bounded, capped shape. function convert(address token) external nonReentrant returns (uint256 amountIn, uint256 quoteOut) { if (!_routes[token].enabled) revert NoRoute(token); return _convert(token, 0); } /// @notice Convert with a floor of the caller's own, on top of the Chainlink one. /// @dev M-01, and the call that finally makes SEC-POT-002 reachable. The keeper-floor /// defence was built into `_convert` in batch 3, but on this contract the only /// caller passed a hardcoded zero — so the parameter existed and the defence did /// not. A keeper holding a real quote can now refuse a worse fill. The floor may /// only be RAISED: `_convert` takes the maximum of this and the Chainlink minimum, /// so a caller can tighten the bound and never widen it. function convert(address token, uint256 callerMinOut) external nonReentrant returns (uint256 amountIn, uint256 quoteOut) { if (!_routes[token].enabled) revert NoRoute(token); return _convert(token, callerMinOut); } /// @notice Set the wrapped-native token so native ETH can be converted. Multisig only. function setWeth(address weth_) external onlyOwner { _setWeth(weth_); } /// @notice Register or update a conversion route. Multisig only. function setRoute( address token, address feed, address router, uint24 fee, uint32 maxSlippageBps, uint128 maxPerCall, uint128 minPerCall, uint64 maxFeedAge ) external onlyOwner { _setRoute(token, feed, router, fee, maxSlippageBps, maxPerCall, minPerCall, maxFeedAge); } /// @notice Stop converting a token. Multisig only. function disableRoute(address token) external onlyOwner { _disableRoute(token); } /* ------------------------------------------------------------------ */ /* VIEWS */ /* ------------------------------------------------------------------ */ function positionCount() external view returns (uint256) { return positionIds.length; } function isPolAsset(address token) public view returns (bool) { return _polAssets[token].registered; } function polAssetOf(address token) external view returns (PolAsset memory) { return _polAssets[token]; } /// @notice The gauge Aerodrome names for a position's pool. Zero if the pool has none. function canonicalGaugeOf(uint256 tokenId) external view returns (address) { (address pool,,) = _positionPool(tokenId); return voter.gauges(pool); } /// @notice Quote-token value of one whole `asset` at its Chainlink mark, and at `pool`. /// @dev Exposed so an operator can see why an operation was refused rather than guessing. function markAndPoolPrice(address asset, address pool) external view returns (uint256 mark, uint256 poolPrice) { PolAsset storage a = _polAssets[asset]; if (!a.registered) revert TokenNotPolAsset(asset); mark = (_readFeed(a.feed, a.maxFeedAge) * (10 ** quoteDecimals)) / (10 ** a.feedDecimals); poolPrice = _poolQuotePerAsset(pool, asset, a.tokenDecimals); } /* ------------------------------------------------------------------ */ /* POSITIONS */ /* ------------------------------------------------------------------ */ /// @notice Open a new Slipstream position. Manager or multisig. /// @dev H-02. The caller chooses the range and the size. It does not choose the tokens, /// the pool, the pool's price, or where the NFT lands. `sqrtPriceX96` is forced to /// zero because that field exists only to CREATE and initialise a pool, and this /// function may only add liquidity to one that already exists and already prices /// correctly. function mintPosition(INonfungiblePositionManager.MintParams calldata params) external onlyManager nonReentrant returns (uint256 tokenId, uint128 liquidity, uint256 amount0, uint256 amount1) { address asset = _requireQuotePaired(params.token0, params.token1); address pool = _requireCanonicalPool(params.token0, params.token1, params.tickSpacing); _requirePoolOnMark(pool, asset); _requireStatedMins(params.amount0Min, params.amount1Min); IERC20(params.token0).forceApprove(address(positionManager), params.amount0Desired); IERC20(params.token1).forceApprove(address(positionManager), params.amount1Desired); INonfungiblePositionManager.MintParams memory p = params; p.recipient = address(this); // never mint to anywhere but here p.sqrtPriceX96 = 0; // never create a pool, only join one that exists (tokenId, liquidity, amount0, amount1) = positionManager.mint(p); IERC20(params.token0).forceApprove(address(positionManager), 0); IERC20(params.token1).forceApprove(address(positionManager), 0); _register(tokenId); emit PositionMinted(tokenId, liquidity, amount0, amount1); } /// @notice Add to an existing position. Manager or multisig. /// @dev The pair is read from the position rather than taken from the caller, so the /// approvals granted here are always for the tokens that position actually holds. /// A caller-supplied pair let a manager approve one token while topping up a /// position in another; there was no legitimate use for the freedom. function increaseLiquidity( uint256 tokenId, uint256 amount0Desired, uint256 amount1Desired, uint256 amount0Min, uint256 amount1Min ) external onlyManager nonReentrant returns (uint128 liquidity, uint256 amount0, uint256 amount1) { if (!holdsPosition[tokenId]) revert UnknownPosition(tokenId); (address pool, address token0, address token1) = _positionPool(tokenId); _requirePoolOnMark(pool, _requireQuotePaired(token0, token1)); _requireStatedMins(amount0Min, amount1Min); IERC20(token0).forceApprove(address(positionManager), amount0Desired); IERC20(token1).forceApprove(address(positionManager), amount1Desired); (liquidity, amount0, amount1) = positionManager.increaseLiquidity( INonfungiblePositionManager.IncreaseLiquidityParams({ tokenId: tokenId, amount0Desired: amount0Desired, amount1Desired: amount1Desired, amount0Min: amount0Min, amount1Min: amount1Min, deadline: block.timestamp }) ); IERC20(token0).forceApprove(address(positionManager), 0); IERC20(token1).forceApprove(address(positionManager), 0); emit LiquidityIncreased(tokenId, liquidity, amount0, amount1); } /// @notice Pull liquidity out of a position, e.g. to re-range. Manager or multisig. /// @dev The withdrawn tokens land in this contract and stay here. There is no path /// from this function to an external wallet. /// /// H-02(d). An exit is the mirror of an entry and was previously the softer of the /// two: `amountMin = 0` let a position be unwound at whatever price the pool happened /// to be showing. The Chainlink band is the real bound here — a manipulated pool is /// refused outright — and blank minimums are refused on top of it, because an /// operator who has not said what they expect is not in a position to notice they /// did not get it. A single-sided exit is normal for an out-of-range position, so /// only one of the two must be stated. function decreaseLiquidity(uint256 tokenId, uint128 liquidity, uint256 amount0Min, uint256 amount1Min) external onlyManager nonReentrant returns (uint256 amount0, uint256 amount1) { if (!holdsPosition[tokenId]) revert UnknownPosition(tokenId); _requireStatedMins(amount0Min, amount1Min); (address pool, address token0, address token1) = _positionPool(tokenId); _requirePoolOnMark(pool, _requireQuotePaired(token0, token1)); (amount0, amount1) = positionManager.decreaseLiquidity( INonfungiblePositionManager.DecreaseLiquidityParams({ tokenId: tokenId, liquidity: liquidity, amount0Min: amount0Min, amount1Min: amount1Min, deadline: block.timestamp }) ); emit LiquidityDecreased(tokenId, amount0, amount1); } /// @notice Collect trading fees from a position. Permissionless. /// @dev Anyone may call it, and the proceeds can only land in this contract, so income /// keeps flowing even if the optimizer stops. function collectFees(uint256 tokenId) public nonReentrant returns (uint256 amount0, uint256 amount1) { if (!holdsPosition[tokenId]) revert UnknownPosition(tokenId); (amount0, amount1) = positionManager.collect( INonfungiblePositionManager.CollectParams({ tokenId: tokenId, recipient: address(this), amount0Max: type(uint128).max, amount1Max: type(uint128).max }) ); emit FeesCollected(tokenId, amount0, amount1); } /// @notice Collect from every position we hold. Permissionless. /// @dev One failing position is skipped rather than reverting the sweep, so a single /// broken or frozen pair cannot stop the others from paying out. The list it walks /// is bounded by construction — see `onERC721Received` and `prunePosition` (M-03). function collectAllFees() external returns (uint256 collected) { uint256 len = positionIds.length; for (uint256 i; i < len; ++i) { try this.collectFees(positionIds[i]) returns (uint256, uint256) { ++collected; } catch {} } } /* ------------------------------------------------------------------ */ /* POSITION BOOKKEEPING */ /* ------------------------------------------------------------------ */ /// @notice Track a position that arrived without being minted here. Multisig only. /// @dev M-03. Auto-registration on receipt now covers only positions minted TO this /// contract, so a deliberate transfer in — a migration, a top-up from the multisig — /// is registered here instead. Owner-gated, because the cost of a junk entry is paid /// by `collectAllFees` forever. function registerPosition(uint256 tokenId) external onlyOwner { if (positionManager.ownerOf(tokenId) != address(this)) revert UnknownPosition(tokenId); _register(tokenId); emit PositionRegistered(tokenId); } /// @notice Forget a position this treasury no longer holds. Manager or multisig. /// @dev M-03, the other half. `positionIds` was append-only, so anything that ever landed /// here was walked by `collectAllFees` forever — a griefer could donate dust /// positions until the sweep ran out of gas. Removal is permitted only for a token /// this contract genuinely no longer owns and has not staked, so it can never be /// used to hide a live position from the fee sweep. function prunePosition(uint256 tokenId) external onlyManager { if (!holdsPosition[tokenId]) revert UnknownPosition(tokenId); if (stakedIn[tokenId] != address(0)) revert PositionStillHeld(tokenId); if (positionManager.ownerOf(tokenId) == address(this)) revert PositionStillHeld(tokenId); holdsPosition[tokenId] = false; uint256 len = positionIds.length; for (uint256 i; i < len; ++i) { if (positionIds[i] == tokenId) { positionIds[i] = positionIds[len - 1]; positionIds.pop(); break; } } emit PositionPruned(tokenId); } /* ------------------------------------------------------------------ */ /* GAUGE STAKING */ /* ------------------------------------------------------------------ */ /// @notice Stake a position in its Aerodrome gauge to earn AERO. Manager or multisig. /// @dev H-01. `stakePosition` grants the gauge an ERC-721 approval and then calls into /// it, so an arbitrary gauge address was an arbitrary `transferFrom` of the position /// — a one-call theft by anyone holding the manager key. The gauge must now be the /// one Aerodrome's voter names for the pool this position is actually in, and the /// pool is derived from `positions(tokenId)` rather than supplied. /// /// The approval is also checked out again: after `deposit` the gauge must own the /// position. A canonical gauge always takes custody, so this both asserts the stake /// happened and guarantees no live approval is left behind — the ERC-721 transfer /// clears it. function stakePosition(uint256 tokenId, address gauge) external onlyManager nonReentrant { if (!holdsPosition[tokenId]) revert UnknownPosition(tokenId); _requireCanonicalGauge(tokenId, gauge); stakedIn[tokenId] = gauge; IERC721Approve(address(positionManager)).approve(gauge, tokenId); ISlipstreamGauge(gauge).deposit(tokenId); if (positionManager.ownerOf(tokenId) != gauge) revert GaugeDidNotCustody(gauge); emit PositionStaked(tokenId, gauge); } /// @notice Withdraw a staked position back to this contract. Manager or multisig. /// @dev Withdrawal goes to the gauge we actually deposited into, recorded at stake time. /// Nothing else is a legitimate counterparty, and remembering is stricter than /// re-deriving: it holds even if the voter's answer for that pool changes later. function unstakePosition(uint256 tokenId, address gauge) external onlyManager nonReentrant { if (!holdsPosition[tokenId]) revert UnknownPosition(tokenId); if (gauge == address(0) || stakedIn[tokenId] != gauge) revert GaugeNotCanonical(gauge); delete stakedIn[tokenId]; ISlipstreamGauge(gauge).withdraw(tokenId); emit PositionUnstaked(tokenId, gauge); } /// @notice Claim AERO for a staked position. Permissionless. /// @dev The gauge is the one we staked into, not one the caller names. As an arbitrary /// `getReward(uint256)` against any address, this was a free call primitive pointed /// wherever a caller liked, made from the contract that holds the treasury's assets. /// There is no reason for it to reach anything but our own gauge. function claimGaugeRewards(uint256 tokenId) external nonReentrant { address gauge = stakedIn[tokenId]; if (gauge == address(0)) revert UnknownPosition(tokenId); ISlipstreamGauge(gauge).getReward(tokenId); } /* ------------------------------------------------------------------ */ /* INCOME */ /* ------------------------------------------------------------------ */ /// @notice Push one income token to the FeeSplitter, where it re-enters the Pot. /// Permissionless. /// @dev One token per call, deliberately. A frozen or paused income token fails only /// its own call and cannot block the others. function forwardIncome(address token) public nonReentrant returns (uint256 amount) { if (!isIncomeToken[token]) revert ProtectedToken(token); amount = IERC20(token).balanceOf(address(this)); if (amount == 0) revert NothingToForward(token); IERC20(token).safeTransfer(feeSplitter, amount); emit IncomeForwarded(token, amount, feeSplitter); } /// @notice Push several income tokens. Empty or failing ones are skipped, so one bad /// token cannot brick the batch. function forwardIncomeMany(address[] calldata tokens) external returns (uint256 forwarded) { for (uint256 i; i < tokens.length; ++i) { try this.forwardIncome(tokens[i]) returns (uint256) { ++forwarded; } catch {} } } /* ------------------------------------------------------------------ */ /* COMPOUND SHARE LEDGER */ /* ------------------------------------------------------------------ */ /// @notice Record that a holder routed a claim into POL instead of taking it. /// @dev Only ChipRewards may call this. ChipRewards treats the call as best-effort so /// a problem here can never block someone's claim; its own counter is the /// authoritative record and this is the POL-side view of the same event. function notifyCompound(address owner, address token, uint256 amount, uint256 usdValue) external { if (msg.sender != rewards) revert NotRewards(msg.sender); compoundShares[owner] += usdValue; totalCompoundShares += usdValue; emit CompoundRecorded(owner, token, amount, usdValue); } /* ------------------------------------------------------------------ */ /* RESCUE */ /* ------------------------------------------------------------------ */ /// @notice True if the rescue is forbidden from moving this token. /// @dev The position manager is named explicitly rather than left to the fact that an /// ERC-721 has no matching `transfer` shape. Relying on the absence of a function /// selector on a third-party contract is a property of THEIR code, not ours, and it /// would stop being true the day the NFPM gained an ERC-20-shaped method. function isProtected(address token) public view returns (bool) { return token == quoteToken || _polAssets[token].registered || isIncomeToken[token] || token == address(positionManager); } /// @notice Recover a token the treasury does not recognise. Multisig only. /// @dev Deliberately narrow: see the rescue rule at the top of this contract. Protocol /// assets are not reachable by this function at any amount. function recoverExcess(address token, address to, uint256 amount) external onlyOwner nonReentrant { if (to == address(0)) revert ZeroAddress(); if (isProtected(token)) revert ProtectedToken(token); uint256 balance = IERC20(token).balanceOf(address(this)); if (amount == 0 || amount > balance) revert NothingToRecover(token); IERC20(token).safeTransfer(to, amount); emit ExcessRecovered(token, to, amount); } /* ------------------------------------------------------------------ */ /* ERC721 */ /* ------------------------------------------------------------------ */ /// @notice Accept position NFTs, and remember the ones minted to us. /// @dev M-03. Registration is limited to `from == address(0)` — a fresh mint into this /// contract. A transfer in from somebody else is accepted (refusing it would let a /// griefer make our own migrations fail) but not tracked, so donated dust cannot /// grow the list `collectAllFees` walks. A deliberate transfer in is picked up by /// `registerPosition`. function onERC721Received(address, address from, uint256 tokenId, bytes calldata) external override returns (bytes4) { if (msg.sender == address(positionManager) && from == address(0)) _register(tokenId); return IERC721Receiver.onERC721Received.selector; } /* ------------------------------------------------------------------ */ /* INTERNALS */ /* ------------------------------------------------------------------ */ function _register(uint256 tokenId) internal { if (!holdsPosition[tokenId]) { holdsPosition[tokenId] = true; positionIds.push(tokenId); } } /// @dev H-02(a). Every POL position is the quote token paired with a registered POL /// asset. Requiring the quote side is stricter than the finding asked for, and /// deliberately so: it is what makes the pool's price checkable against a single /// USD feed, and a POL/POL pair is not something this treasury has any reason to /// hold. Adding an asset is a multisig call; adding a pair shape is a code change. function _requireQuotePaired(address token0, address token1) internal view returns (address asset) { if (token0 == quoteToken) asset = token1; else if (token1 == quoteToken) asset = token0; else revert NotQuotePaired(); if (!_polAssets[asset].registered) revert TokenNotPolAsset(asset); } /// @dev H-02(b). The pool is whatever the position manager's own factory says it is. function _requireCanonicalPool(address token0, address token1, int24 tickSpacing) internal view returns (address pool) { pool = ISlipstreamFactory(positionFactory).getPool(token0, token1, tickSpacing); if (pool == address(0)) revert PoolNotCanonical(pool); } /// @dev The pool a position lives in, plus its pair. Derived, never supplied. function _positionPool(uint256 tokenId) internal view returns (address pool, address token0, address token1) { int24 tickSpacing; (,, token0, token1, tickSpacing,,,,,,,) = positionManager.positions(tokenId); pool = _requireCanonicalPool(token0, token1, tickSpacing); } /// @dev H-01. A gauge is only a gauge because the voter says so, for the pool this /// position is actually in. function _requireCanonicalGauge(uint256 tokenId, address gauge) internal view { (address pool,,) = _positionPool(tokenId); if (gauge == address(0) || voter.gauges(pool) != gauge) revert GaugeNotCanonical(gauge); } /// @dev H-02(c). Liquidity moves only while the pool agrees with Chainlink. /// /// This is the check that makes the pool derivation meaningful. Deriving the pool /// stops a caller inventing one; the band stops them using a real-but-thin pool for /// the same pair that they have just pushed to an absurd price. Both halves are /// needed — either alone leaves a way to enter or exit at a price the treasury never /// agreed to. function _requirePoolOnMark(address pool, address asset) internal view { PolAsset storage a = _polAssets[asset]; uint256 mark = (_readFeed(a.feed, a.maxFeedAge) * (10 ** quoteDecimals)) / (10 ** a.feedDecimals); uint256 poolPrice = _poolQuotePerAsset(pool, asset, a.tokenDecimals); uint256 tolerance = (mark * a.maxDeviationBps) / BPS; uint256 delta = poolPrice > mark ? poolPrice - mark : mark - poolPrice; if (delta > tolerance) revert PoolPriceOffMark(poolPrice, mark); } /// @dev Quote-token units one whole unit of `asset` costs, at the pool's current price. /// `slot0` is read by staticcall and decoded as a single word: Uniswap v3 and /// Slipstream return different tuples and agree only on the first field, which is /// the one we want. function _poolQuotePerAsset(address pool, address asset, uint8 assetDecimals) internal view returns (uint256) { (bool ok, bytes memory ret) = pool.staticcall(abi.encodeWithSignature("slot0()")); if (!ok || ret.length < 32) revert PoolPriceUnavailable(pool); // Read the first returned word directly. `abi.decode` would tie us to one tuple // arity, and the whole point is that we do not care about the fields after the price. uint256 word; assembly { word := mload(add(ret, 32)) } uint256 sqrtPriceX96 = uint256(uint160(word)); if (sqrtPriceX96 == 0) revert PoolPriceUnavailable(pool); uint256 q96 = 1 << 96; // token1 per token0, in raw units, Q96-scaled. uint256 priceX96 = Math.mulDiv(sqrtPriceX96, sqrtPriceX96, q96); uint256 whole = 10 ** assetDecimals; // Pools sort by address. If the asset is token0 the pool already quotes it in the // quote token; if it is token1 the ratio is the other way up and must be inverted. return asset < quoteToken ? Math.mulDiv(priceX96, whole, q96) : Math.mulDiv(whole, q96, priceX96); } /// @dev H-02(c)/(d). Blank minimums are refused on every liquidity operation. /// /// WHAT ACTUALLY BOUNDS EXECUTION IS THE BAND, NOT THIS. It is worth being precise, /// because a check that looks like the protection but is not would be worse than /// none. `_requirePoolOnMark` has already established that the pool agrees with /// Chainlink, and there is no external call between that check and the position /// manager call — the tokens are allowlisted, so nothing in the pair can reenter and /// move the pool in between. Liquidity therefore enters and leaves at a price the /// treasury has verified, and its value is bounded by that. /// /// This rule is hygiene on top: an operator who states no expectation cannot notice /// they did not get it. It deliberately does NOT require the minimums to track the /// desired amounts, because in concentrated liquidity `amountDesired` is a maximum /// and a range sitting on one side of the current price legitimately consumes zero /// of the other token. A ratio rule would refuse ordinary range orders, which is why /// only one side must be stated. function _requireStatedMins(uint256 min0, uint256 min1) internal pure { if (min0 == 0 && min1 == 0) revert SlippageUnbounded(); } } interface IERC721Approve { function approve(address to, uint256 tokenId) external; }